cbcvebase.
CVE-2019-19965
published 2019-12-25

CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection…

medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 5.4.13-1 (bookworm)linux 5.4.13-1 (bookworm)
linuxlinux_kernel<= 5.4.6
linuxlinux_kernel>= 0 < 5.4.13-15.4.13-1
linuxlinux_kernel>= 0 < 5.4.13-15.4.13-1
linuxlinux_kernel>= 0 < 5.4.13-15.4.13-1
linuxlinux_kernel>= 0 < 5.4.13-15.4.13-1
linuxlinux_kernel>= 0 < 4.4.0-174.2044.4.0-174.204
linuxlinux_kernel>= 0 < 4.15.0-88.884.15.0-88.88
netappe-series_santricity_os_controller11.0.0 – 11.70.1
opensuseleap

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM