# CVE-2026-72131

## Summary

- **CVE ID:** CVE-2026-72131
- **Severity:** UNKNOWN
- **CVSS Score:** 1.01
- **CWE:** N/A
- **Published:** Aug 15, 2026
- **Last Modified:** Sep 16, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

nvme-apple: Prevent shared tags across queues on Apple A11

On Apple A11, tags of pending commands must be unique across the admin
and IO queues, else the firmware crashes with
"duplicate tag error for tag N", with N being the tag.

Apply the existing workaround for M1 of reserving two tags for the admin
queue to A11.

## Affected Products

- Linux — Linux (04d8ecf37b5e06d16228a4d37d8548c17cf70461)
- Linux — Linux (6.18)
- Linux — Linux (0)
- Linux — Linux (6.18.40)
- Linux — Linux (7.1.5)
- Linux — Linux (7.2-rc1)
- Linux — Linux (7.2)
- Linux — Linux (655b6743bd900df39354e8bb6f1f2f8671fca004)
- Linux — Linux (7256eed48ce7d78ab9689d84135b77a15454de55)
- Linux — Linux (89c00b34551e2478041a485b88cf021f1c63228f)

## References

- [CNA](https://git.kernel.org/stable/c/59cef6abc924a84824b0c3f563a7fe74cd5fc7a4)
- [CNA](https://git.kernel.org/stable/c/b7d9aaedf024bb6c0bb6a205848861d888eb1afa)
- [CNA](https://git.kernel.org/stable/c/6fe0687245e8406bf26143bd45eb16441bbe5280)
- [CNA](https://git.kernel.org/stable/c/91d3b243bffe5c94503c9a8ea478a080f79ec58e)
- [CNA](https://git.kernel.org/stable/c/073b9238fac4d1c7727c1d05e3fafad0fd40d451)
- [CNA](https://git.kernel.org/stable/c/c6a1c94c6705e18e9718737be84d5e6e661f134c)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 10.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._