๐Ÿ” CVE Alert

CVE-2026-89790

UNKNOWN 0.0

ipv6: avoid divide by zero in rt6_multipath_rebalance

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid divide by zero in rt6_multipath_rebalance rt6_multipath_rebalance() calculates the total eligible nexthop weight in one pass and programs upper bounds in a second pass. Since RTM_NEWROUTE is RTNL-free, a concurrent ignore_routes_with_linkdown update can make the first pass return zero while the second sees an eligible nexthop, causing rt6_upper_bound_set() to divide by zero. UBSAN: division-overflow in net/ipv6/route.c:4845:17 Oops: divide error: 0000 [#1] SMP KASAN NOPTI rt6_upper_bound_set() net/ipv6/route.c:4845 rt6_multipath_rebalance() fib6_add_rt2node() ip6_route_multipath_add() inet6_rtm_newroute() Skip upper-bound calculation when the first pass reports a zero total. This respects the lock-free performance considerations here and solves insecure scenarios.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
bd11ff421d36abdb585b9104fa70057bf01b3110 < f30cf8fd9872299c0c27f9916252ba2b9f422dce bd11ff421d36abdb585b9104fa70057bf01b3110 < f82b5dbb2fef65b52a62d5ffe05e0483c4385a83 bd11ff421d36abdb585b9104fa70057bf01b3110 < d2c26c2911dd1a363c488add4fb63eb5f0f28f87
Linux / Linux
6.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f30cf8fd9872299c0c27f9916252ba2b9f422dce git.kernel.org: https://git.kernel.org/stable/c/f82b5dbb2fef65b52a62d5ffe05e0483c4385a83 git.kernel.org: https://git.kernel.org/stable/c/d2c26c2911dd1a363c488add4fb63eb5f0f28f87