Divide by Zero Vulnerability in Linux Kernel's IPv6 Multipath Routing
CVE-2026-89790

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-89790?

A vulnerability in the Linux kernel's IPv6 routing logic could cause a divide by zero error during the processing of multipath routes. Specifically, the function rt6_multipath_rebalance() may return zero in its first pass due to concurrent updates, leading to a potential crash or undefined behavior when attempting to calculate upper bounds in a second pass. This vulnerability highlights the need for careful handling of concurrent updates in routing tables to avert security issues and ensure stability in multipath routing scenarios.

Affected Version(s)

Linux bd11ff421d36abdb585b9104fa70057bf01b3110

Linux bd11ff421d36abdb585b9104fa70057bf01b3110

Linux bd11ff421d36abdb585b9104fa70057bf01b3110

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.