Improper resource shutdown or release in Linux kernel - CVE-2026-72031
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper device power state handling in libata-core for the PNY CS900 1TB SSD when entering device-initiated slumber during idle. A local user can trigger idle conditions to cause a denial of service.
The issue can cause the SATA link to go down and not recover, forcing the filesystem read-only.