rootpwn

high · CVSS v3 7.1

CVE-2026-93152

In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Use acquire/release for queue enabled st…

Description

In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Use acquire/release for queue enabled state apple_nvme_init_queue() initializes queue state and then marks the queue enabled. The interrupt and request paths check enabled before using that queue state. The old wmb() after WRITE_ONCE(enabled, true) does not publish the earlier initialization before enabled becomes visible. Use a release store when enabling the queue and acquire loads when testing it. Although the shutdown-side enabled accesses are not used for publishing queue initialization, use helpers for them as well for consistency.

Scores

Severity
high
CVSS v2
3.3
CVSS v3
7.1
CVSS v4
EPSS

← All CVEs