{"id":"CVE-2026-72010","summary":"cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed\n\nCreating a child cpuset where cpuset.mems is never set leads to a div/0\nwhen a VMA mempolicy with MPOL_F_RELATIVE_NODES rebinds in response to a\nCPU hotplug event.\n\nReproduction steps:\n 1) Create a cgroup w/ cpuset controls (do not set cpuset.mems)\n 2) Move the task into the child cpuset\n 3) Create a VMA mempolicy for that task with MPOL_F_RELATIVE_NODES\n 4) unplug and hotplug a cpu\n      echo 0 \u003e /sys/devices/system/cpu/cpu1/online\n      echo 1 \u003e /sys/devices/system/cpu/cpu1/online\n 5) mempolicy rebind does a div/0 in mpol_relative_nodemask on the\n    call to __nodes_fold()\n\nThe cpuset code passes (cs-\u003emems_allowed) which is not guaranteed to have\nnodes to the rebind routine.  Use cs-\u003eeffective_mems instead, which is\nguaranteed to have a non-empty nodemask once we reach that code path.\n\n[ david: add a comment, slightly rephrase description ]","modified":"2026-08-16T03:48:30.673215691Z","published":"2026-08-15T05:51:39.755Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72010.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/02f67c4f88be8e3dbd91951d13cdcc5bcc82e9c7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4b06449384b9ee5b3372bab60601ba5cd4162086"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b7adeba2a21c98c7b20f18e27e3ead86bdb5e08d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b983c56426383e4a06fa5970c4e33cee879b1482"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c17f06d8a085d6be58b544a440ce243f5e441a60"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c844b7d9a9586de15dd28c06da5cc7f6ab28787d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fc680afc510157f6b137956011c09abc23eb0842"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fcc8c310539c3cc523419113b227161a96b50550"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72010.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72010"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ae1c802382f7af60aa54879fb4f5920a9df1ff48"},{"fixed":"b7adeba2a21c98c7b20f18e27e3ead86bdb5e08d"},{"fixed":"fcc8c310539c3cc523419113b227161a96b50550"},{"fixed":"4b06449384b9ee5b3372bab60601ba5cd4162086"},{"fixed":"02f67c4f88be8e3dbd91951d13cdcc5bcc82e9c7"},{"fixed":"fc680afc510157f6b137956011c09abc23eb0842"},{"fixed":"c844b7d9a9586de15dd28c06da5cc7f6ab28787d"},{"fixed":"c17f06d8a085d6be58b544a440ce243f5e441a60"},{"fixed":"b983c56426383e4a06fa5970c4e33cee879b1482"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72010.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.17.0"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72010.json"}}],"schema_version":"1.9.0"}