CVE-2026-43487: ata: libata-core: Disable LPM on ST1000DM010-2EP102
In the Linux kernel, the following vulnerability has been resolved:
ata: libata-core: Disable LPM on ST1000DM010-2EP102
According to a user report, the ST1000DM010-2EP102 has problems with LPM, causing random system freezes. The drive belongs to the same BarraCuda family as the ST2000DM008-2FR102 which has the same issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel (libata-core)to a version that resolves this vulnerability.Patch Disable LPM on ST1000DM010-2EP102 - Configuration
In the Linux kernel’s libata-core, disable LPM specifically on ST1000DM010-2EP102 to prevent random system freezes.
ata: libata-core LPM (Link Power Management) = Disable
Event History
Frequently Asked Questions
Which systems are most likely to experience this issue?
Systems running the Linux kernel with an ST1000DM010-2EP102 drive are affected when SATA Link Power Management (LPM) is used. The reported impact is random system freezes.
What is the practical mitigation if an updated kernel cannot be installed immediately?
Disable LPM for the affected ST1000DM010-2EP102 drive. The kernel fix does this by disabling LPM for that drive model.
Does exploiting this issue require remote access or user interaction?
No. The CVSS vector indicates local access, low attack complexity, low privileges, and no user interaction. The reported condition is tied to LPM behavior on the affected drive rather than a remote attack path.