Executive brief
The Linux kernel's nvme-apple driver has a firmware crash bug on Apple A11 chips when NVMe command tags are not unique across admin and IO queues. The firmware encounters a "duplicate tag error" and crashes, causing loss of storage access and potential data corruption or loss.
Technical details
This is a resource allocation bug (duplicate tag handling) in the nvme-apple kernel driver affecting Apple A11 systems. The vulnerability occurs when pending NVMe command tags are shared across admin and IO queues, violating the firmware's requirement for globally unique tags. The fix applies the existing M1 workaround to A11 by reserving the first APPLE_NVME_AQ_DEPTH tags for the admin queue and marking them as reserved in the IO queue tagset. The vulnerability is local to systems running the affected kernel versions with Apple A11 hardware; it cannot be exploited remotely. A patch was committed upstream and backported to stable kernel branches.
Affected products
- Linux Linux kernel all versions with Apple A11 support (nvme-apple driver)
Timeline
- 2026-06-07: other: Fix authored by Nick Chan
- 2026-08-15: disclosed: CVE-2026-72131 published
- 2026-09-14: patched: Fix committed to stable kernel trees
- 2026-09-21: patched: Apple A11 support reverted in some stable branches