{"id":"CVE-2019-19965","title":"In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.","summary":"In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-476"],"vendor":"netapp","product":"active_iq_unified_manager","affected":["linux_kernel <= 5.4.6","debian_linux = 8.0","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","ubuntu_linux = 19.10","active_iq_unified_manager","cloud_backup","data_availability_services","e-series_santricity_os_controller >= 11.0.0, <= 11.70.1","hci_management_node","solidfire","steelstore_cloud_integrated_storage","leap = 15.1","a700s_firmware","h610s_firmware","8300_firmware","8700_firmware","a400_firmware"],"published":"2019-12-25","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:19.540","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-19965","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html","label":"cve@mitre.org"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f70267f379b5e5e11bdc5d72a56bf17e5feed01f","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20200204-0002/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4284-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4285-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4286-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4286-2/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4287-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4287-2/","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f70267f379b5e5e11bdc5d72a56bf17e5feed01f","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200204-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4284-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4285-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4286-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4286-2/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4287-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4287-2/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00654,"epssPercentile":0.49751,"ingestedAt":"2026-10-08T22:11:53.709Z","slug":"CVE-2019-19965","body":"## Overview\n\nIn the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.\n\n## Affected\n\n- `linux_kernel <= 5.4.6`\n- `debian_linux = 8.0`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 19.10`\n- `active_iq_unified_manager`\n- `cloud_backup`\n- `data_availability_services`\n- `e-series_santricity_os_controller >= 11.0.0, <= 11.70.1`\n- `hci_management_node`\n- `solidfire`\n- `steelstore_cloud_integrated_storage`\n- `leap = 15.1`\n- `a700s_firmware`\n- `h610s_firmware`\n- `8300_firmware`\n- `8700_firmware`\n- `a400_firmware`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}