{"apiVersion":"1.0","identifier":"CVE-2026-72010","description":"In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed Creating a child cpuset where cpuset.mems is never set leads to a div/0 when a VMA mempolicy with MPOL_F_RELATIVE_NODES rebinds in response to a CPU hotplug event. Reproduction steps: 1) Create a cgroup w/ cpuset controls (do not set cpuset.mems) 2) Move the task into the child cpuset 3) Create a VMA mempolicy for that task with MPOL_F_RELATIVE_NODES 4) unplug and hotplug a cpu echo 0 > /sys/devices/system/cpu/cpu1/online echo 1 > /sys/devices/system/cpu/cpu1/online 5) mempolicy rebind does a div/0 in mpol_relative_nodemask on the call to __nodes_fold() The cpuset code passes (cs->mems_allowed) which is not guaranteed to have nodes to the rebind routine. Use cs->effective_mems instead, which is guaranteed to have a non-empty nodemask once we reach that code path. [ david: add a comment, slightly rephrase description ]","publishedAt":"2026-08-15T06:20:59","lastModifiedAt":"2026-08-17T06:17:58","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72010","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00216,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72010","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72010","en":"https://www.redsauce.net/en/cves/CVE-2026-72010","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72010","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72010","de":"https://www.redsauce.net/de/cves/CVE-2026-72010","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72010","el":"https://www.redsauce.net/el/cves/CVE-2026-72010"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72010"}}