GPU VulnDB

Database/Firmware, BMC & network fabric

Phison PS3111-S11 SSD firmware: vendor unique commands allow persistent implants in controller flash

CVE-2026-84696Firmware, BMC & network fabriccurated

Impact

A local user who already holds privileged raw ATA access to the drive can defeat the CRC-16 based unlock handshake - or find builds with no VUC lock at all - and then read and write controller memory and raw NAND directly. That yields an implant below the filesystem that survives power cycles, OS reinstall and reimaging, which is precisely the boundary a GPU operator relies on when recycling a node between tenants or jobs. Exposure depends on the fleet: PS3111-S11 is an entry-level SATA controller, most often found in cheap boot or scratch SSDs rather than enterprise NVMe, so the first task is inventory. The record establishes firmware read/write and persistence; it does not describe a remote or unprivileged path.

Who can reach it

Local user able to issue raw ATA passthrough commands to the drive - root or equivalent holding the block device. No network exposure and no valid credential is needed once the vendor-command lock is bypassed.

What to do

The record names no fixed firmware version - everything through SBFQT1.3 is affected and no vendor patch is cited - so treat this as mitigate-only for now. Inventory which nodes carry PS3111-S11 based drives, restrict raw ATA passthrough to the drive from tenant and non-root contexts, and stop trusting reimaging alone to clean a suspect boot drive: physically replace it instead. If a drive OEM later ships fixed firmware, flashing it takes the node out of service.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.