imPC@ndo IT

Tracker / CVE-2019-19965

CVE-2019-19965

Medium 4.7

In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.

Affected products and versions

canonical ubuntu_linux
debian debian_linux
linux linux_kernel · … → 5.4.6
netapp 8300_firmware
netapp 8700_firmware
netapp a400_firmware
netapp a700s_firmware
netapp active_iq_unified_manager
netapp cloud_backup
netapp data_availability_services
netapp e-series_santricity_os_controller · 11.0.0 → 11.70.1
netapp h610s_firmware
netapp hci_management_node
netapp solidfire
netapp steelstore_cloud_integrated_storage
opensuse leap

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References