Description
In the Linux kernel, the following vulnerability has been resolved:

nvme-apple: Use acquire/release for queue enabled state

apple_nvme_init_queue() initializes queue state and then marks the queue
enabled. The interrupt and request paths check enabled before using that
queue state.

The old wmb() after WRITE_ONCE(enabled, true) does not publish the
earlier initialization before enabled becomes visible. Use a release store
when enabling the queue and acquire loads when testing it.

Although the shutdown-side enabled accesses are not used for publishing
queue initialization, use helpers for them as well for consistency.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Race Condition Potential Data Corruption
Action: Patch
AI Analysis

Impact

The vulnerability in the Linux kernel arises when the nvme-apple driver initializes a queue and immediately marks it as enabled without using a release memory ordering. This omission means that the earlier initialization may not be visible to other CPUs before the enabled flag is read in interrupt or request paths, giving rise to a race condition where an operation could proceed on an uninitialized queue. The result could be data corruption or kernel instability and is rooted in a concurrency bug involving improper acquire/release semantics.

Affected Systems

All Linux kernel builds that include the nvme-apple driver before the fix are affected. The flaw applies to the general Linux kernel and the Apple integration within it, covering all releases that contain the nvme-apple code prior to the commit that introduced acquire/release fences. No explicit version numbers are listed, so any kernel module built from the unpatched source is considered vulnerable.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability does not appear in the CISA KEV catalog, indicating a low likelihood of exploitation. While the CVSS assessment is unspecified, the race condition could lead to unpredictable kernel behavior or data corruption. An attacker would need local kernel or privileged code execution to manipulate the nvme-apple queue state, making the risk moderate but unlikely to be actively targeted.

Generated by OpenCVE AI on September 19, 2026 at 07:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to include the latest nvme-apple driver code that implements acquire/release fencing and rebuild the module with the patched source.
  • Reboot the system or reload the nvme-apple module after the kernel update so the corrected memory ordering is applied.
  • If an immediate kernel update is not possible, blacklist the nvme-apple driver by adding a blacklist entry to /etc/modprobe.d or the initramfs to prevent the module from loading and thereby avoid the race condition.

Generated by OpenCVE AI on September 19, 2026 at 07:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Use acquire/release for queue enabled state apple_nvme_init_queue() initializes queue state and then marks the queue enabled. The interrupt and request paths check enabled before using that queue state. The old wmb() after WRITE_ONCE(enabled, true) does not publish the earlier initialization before enabled becomes visible. Use a release store when enabling the queue and acquire loads when testing it. Although the shutdown-side enabled accesses are not used for publishing queue initialization, use helpers for them as well for consistency.
Title nvme-apple: Use acquire/release for queue enabled state
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:48.782Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93152

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:10.480

Modified: 2026-09-17T17:18:10.480

Link: CVE-2026-93152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:00:11Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')