Re: [PATCH net] ipv6: avoid divide by zero in rt6_multipath_rebalance

From: Ido Schimmel

Date: Wed Aug 19 2026 - 11:19:23 EST


On Sun, Aug 16, 2026 at 09:32:37PM -0400, Cen Zhang (Microsoft) wrote:
> rt6_multipath_rebalance() calculates the total eligible nexthop weight
> in one pass and programs upper bounds in a second pass. Since
> RTM_NEWROUTE is RTNL-free, a concurrent
> ignore_routes_with_linkdown update can make the first pass return zero
> while the second sees an eligible nexthop, causing
> rt6_upper_bound_set() to divide by zero.
>
> UBSAN: division-overflow in net/ipv6/route.c:4845:17
> Oops: divide error: 0000 [#1] SMP KASAN NOPTI
> rt6_upper_bound_set() net/ipv6/route.c:4845
> rt6_multipath_rebalance()
> fib6_add_rt2node()
> ip6_route_multipath_add()
> inet6_rtm_newroute()
>
> Skip upper-bound calculation when the first pass reports a zero total.
> This respects the lock-free performance considerations here and solves
> insecure scenarios.
>
> Fixes: bd11ff421d36 ("ipv6: Get rid of RTNL for SIOCDELRT and RTM_DELROUTE.")
> Reported-by: AutonomousCodeSecurity@xxxxxxxxxxxxx
> Reported-by: Xiang Mei (Microsoft) <xmei5@xxxxxxx>
> Reported-by: Cen Zhang (Microsoft) <blbllhy@xxxxxxxxx>
> Signed-off-by: Cen Zhang (Microsoft) <blbllhy@xxxxxxxxx>

Reviewed-by: Ido Schimmel <idosch@xxxxxxxxxx>

FYI:

"Patch authors are expected to proactively look into the AI-generated
reviews and handle such feedback as any other kind of review: either
debate it or address it. In both cases a reply on the mailing list is
expected."

https://docs.kernel.org/next/process/maintainer-netdev.html#review-timelines

I went over the feedback from Sashiko [1]. Most of it is correct, but
irrelevant.

Changing the value of "ignore_routes_with_linkdown" on the fly never
worked correctly and it is not interesting: It is expected that the user
configures it during initialization, not after configuring routes.

When this sysctl is changed, the kernel does not iterate over all the
nexthop groups and rebalances them. For example, if we have two nexthops
in a group, one is down and now we set "ignore_routes_with_linkdown" to
1, the kernel can still pick the down nexthop until some event causes
the group to be rebalanced.

Also note that this only affects legacy nexthop groups. Nexthop objects
do not make use of "ignore_routes_with_linkdown".

[1] https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260817013237.2797-1-blbllhy%40gmail.com