CVE-2026-72131

medium

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Prevent shared tags across queues on Apple A11 On Apple A11, tags of pending commands must be unique across the admin and IO queues, else the firmware crashes with "duplicate tag error for tag N", with N being the tag. Apply the existing workaround for M1 of reserving two tags for the admin queue to A11.

References

https://git.kernel.org/stable/c/b7d9aaedf024bb6c0bb6a205848861d888eb1afa

https://git.kernel.org/stable/c/91d3b243bffe5c94503c9a8ea478a080f79ec58e

https://git.kernel.org/stable/c/6fe0687245e8406bf26143bd45eb16441bbe5280

https://git.kernel.org/stable/c/59cef6abc924a84824b0c3f563a7fe74cd5fc7a4

https://git.kernel.org/stable/c/2c4baeb1747775d23a0c9d6e9f49e3d9417e3b6d

https://git.kernel.org/stable/c/073b9238fac4d1c7727c1d05e3fafad0fd40d451

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-09-21

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Severity: High

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00198