{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed  Creating a child cpuset where cpuset.mems is never set leads to a div/0 when a VMA mempolicy with MPOL_F_RELATIVE_NODES rebinds in response to a CPU hotplug event.  Reproduction steps:  1) Create a cgroup w/ cpuset controls (do not set cpuset.mems)  2) Move the task into the child cpuset  3) Create a VMA mempolicy for that task with MPOL_F_RELATIVE_NODES  4) unplug and hotplug a cpu       echo 0 \u003e /sys/devices/system/cpu/cpu1/online       echo 1 \u003e /sys/devices/system/cpu/cpu1/online  5) mempolicy rebind does a div/0 in mpol_relative_nodemask on the     call to __nodes_fold()  The cpuset code passes (cs-\u003emems_allowed) which is not guaranteed to have nodes to the rebind routine.  Use cs-\u003eeffective_mems instead, which is guaranteed to have a non-empty nodemask once we reach that code path.  [ david: add a comment, slightly rephrase description ]",
  "id": "DEBIAN-CVE-2026-72010",
  "modified": "2026-09-14T16:47:28.713756628Z",
  "published": "2026-08-15T06:20:59.670Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-72010"
    }
  ],
  "upstream": [
    "CVE-2026-72010"
  ]
}