{"api_version":"1","generated_at":"2026-08-21T19:13:09+00:00","cve":"CVE-2026-72131","urls":{"html":"https://cve.report/CVE-2026-72131","api":"https://cve.report/api/cve/CVE-2026-72131.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-72131","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-72131"},"summary":{"title":"nvme-apple: Prevent shared tags across queues on Apple A11","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-apple: Prevent shared tags across queues on Apple A11\n\nOn Apple A11, tags of pending commands must be unique across the admin\nand IO queues, else the firmware crashes with\n\"duplicate tag error for tag N\", with N being the tag.\n\nApply the existing workaround for M1 of reserving two tags for the admin\nqueue to A11.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:21:30","updated_at":"2026-08-17 06:18:12"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/b7d9aaedf024bb6c0bb6a205848861d888eb1afa","name":"https://git.kernel.org/stable/c/b7d9aaedf024bb6c0bb6a205848861d888eb1afa","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/59cef6abc924a84824b0c3f563a7fe74cd5fc7a4","name":"https://git.kernel.org/stable/c/59cef6abc924a84824b0c3f563a7fe74cd5fc7a4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6fe0687245e8406bf26143bd45eb16441bbe5280","name":"https://git.kernel.org/stable/c/6fe0687245e8406bf26143bd45eb16441bbe5280","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72131","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72131","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 04d8ecf37b5e06d16228a4d37d8548c17cf70461 59cef6abc924a84824b0c3f563a7fe74cd5fc7a4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 04d8ecf37b5e06d16228a4d37d8548c17cf70461 b7d9aaedf024bb6c0bb6a205848861d888eb1afa git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 04d8ecf37b5e06d16228a4d37d8548c17cf70461 6fe0687245e8406bf26143bd45eb16441bbe5280 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"72131","cve":"CVE-2026-72131","epss":"0.001980000","percentile":"0.099040000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/nvme/host/apple.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"59cef6abc924a84824b0c3f563a7fe74cd5fc7a4","status":"affected","version":"04d8ecf37b5e06d16228a4d37d8548c17cf70461","versionType":"git"},{"lessThan":"b7d9aaedf024bb6c0bb6a205848861d888eb1afa","status":"affected","version":"04d8ecf37b5e06d16228a4d37d8548c17cf70461","versionType":"git"},{"lessThan":"6fe0687245e8406bf26143bd45eb16441bbe5280","status":"affected","version":"04d8ecf37b5e06d16228a4d37d8548c17cf70461","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/nvme/host/apple.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.18"},{"lessThan":"6.18","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"6.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"6.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"6.18","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-apple: Prevent shared tags across queues on Apple A11\n\nOn Apple A11, tags of pending commands must be unique across the admin\nand IO queues, else the firmware crashes with\n\"duplicate tag error for tag N\", with N being the tag.\n\nApply the existing workaround for M1 of reserving two tags for the admin\nqueue to A11."}],"providerMetadata":{"dateUpdated":"2026-08-17T05:08:48.421Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/59cef6abc924a84824b0c3f563a7fe74cd5fc7a4"},{"url":"https://git.kernel.org/stable/c/b7d9aaedf024bb6c0bb6a205848861d888eb1afa"},{"url":"https://git.kernel.org/stable/c/6fe0687245e8406bf26143bd45eb16441bbe5280"}],"title":"nvme-apple: Prevent shared tags across queues on Apple A11","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-72131","datePublished":"2026-08-15T05:53:07.349Z","dateReserved":"2026-08-09T03:40:39.907Z","dateUpdated":"2026-08-17T05:08:48.421Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:21:30","lastModifiedDate":"2026-08-17 06:18:12","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"72131","Ordinal":"1","Title":"nvme-apple: Prevent shared tags across queues on Apple A11","CVE":"CVE-2026-72131","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"72131","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-apple: Prevent shared tags across queues on Apple A11\n\nOn Apple A11, tags of pending commands must be unique across the admin\nand IO queues, else the firmware crashes with\n\"duplicate tag error for tag N\", with N being the tag.\n\nApply the existing workaround for M1 of reserving two tags for the admin\nqueue to A11.","Type":"Description","Title":"nvme-apple: Prevent shared tags across queues on Apple A11"}]}}}