Junglewise Threat Intelligence

CVE-2026-72031: Linux kernel libata power management incompatibility with PNY CS900 SSD

CVE-2026-72031 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The PNY CS900 1TB SSD has a hardware incompatibility with the Linux kernel's default power management policy, causing the drive to become unreachable during idle periods and forcing the filesystem into read-only mode. Systems using this drive will experience service interruptions and data unavailability until the system is rebooted or manually intervened. The fix disables link power management specifically for this drive model, restoring stable operation.

Technical details

This is a hardware incompatibility issue in the Linux kernel's libata (ATA library) subsystem when handling the PNY CS900 1TB SSD (based on Phison PS3111-S11 controller, DRAM-less variant). The problem occurs when the SSD enters Device-Initiated Slumber (DIPM) during idle with the default med_power_with_dipm power policy; the SATA link drops (SStatus 1, SControl 300) and fails to recover, leaving the drive inaccessible. The fix adds a NOLPM (No Link Power Management) quirk in the libata-core.c driver to disable power management for this specific drive model, while leaving power management intact for other devices. No security exploit is possible; this is purely a reliability/availability fix.

Affected products

  • Linux Linux kernel all versions with libata support (approximately 2.6.11+)

Timeline

  • 2026-06-19: other: Patch authored
  • 2026-07-03: disclosed: Upstream patch merged
  • 2026-07-24: patched: Patch merged into stable kernel releases
  • 2026-08-15: advisory: CVE-2026-72031 published

References

Related threats