CVE-2026-72131

Source
https://cve.org/CVERecord?id=CVE-2026-72131
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72131.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72131
Downstream
Published
2026-08-15T05:53:07.349Z
Modified
2026-08-18T03:31:04.438460617Z
Summary
nvme-apple: Prevent shared tags across queues on Apple A11
Details

In the Linux kernel, the following vulnerability has been resolved:

nvme-apple: Prevent shared tags across queues on Apple A11

On Apple A11, tags of pending commands must be unique across the admin and IO queues, else the firmware crashes with "duplicate tag error for tag N", with N being the tag.

Apply the existing workaround for M1 of reserving two tags for the admin queue to A11.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72131.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
04d8ecf37b5e06d16228a4d37d8548c17cf70461
Fixed
59cef6abc924a84824b0c3f563a7fe74cd5fc7a4
Fixed
b7d9aaedf024bb6c0bb6a205848861d888eb1afa
Fixed
6fe0687245e8406bf26143bd45eb16441bbe5280

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72131.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72131.json"