nvme-apple: Prevent shared tags across queues on Apple A11
Summary
| CVE | CVE-2026-72131 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:21:30 UTC |
| Updated | 2026-08-17 06:18:12 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Prevent shared tags across queues on Apple A11 On Apple A11, tags of pending commands must be unique across the admin and IO queues, else the firmware crashes with "duplicate tag error for tag N", with N being the tag. Apply the existing workaround for M1 of reserving two tags for the admin queue to A11. |
Risk And Classification
EPSS: 0.001980000 probability, percentile 0.099040000 (date 2026-08-17)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 04d8ecf37b5e06d16228a4d37d8548c17cf70461 59cef6abc924a84824b0c3f563a7fe74cd5fc7a4 git | Not specified |
| CNA | Linux | Linux | affected 04d8ecf37b5e06d16228a4d37d8548c17cf70461 b7d9aaedf024bb6c0bb6a205848861d888eb1afa git | Not specified |
| CNA | Linux | Linux | affected 04d8ecf37b5e06d16228a4d37d8548c17cf70461 6fe0687245e8406bf26143bd45eb16441bbe5280 git | Not specified |
| CNA | Linux | Linux | affected 6.18 | Not specified |
| CNA | Linux | Linux | unaffected 6.18 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.40 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.5 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/b7d9aaedf024bb6c0bb6a205848861d888eb1afa | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/59cef6abc924a84824b0c3f563a7fe74cd5fc7a4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6fe0687245e8406bf26143bd45eb16441bbe5280 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.