CVE-2019-19965Medium· 4.7▾ SunlitIn the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
linux_kernel <= 5.4.6debian_linux = 8.0ubuntu_linux = 14.04ubuntu_linux = 16.04ubuntu_linux = 18.04ubuntu_linux = 19.10active_iq_unified_managercloud_backupdata_availability_servicese-series_santricity_os_controller >= 11.0.0, <= 11.70.1hci_management_nodesolidfiresteelstore_cloud_integrated_storageleap = 15.1a700s_firmwareh610s_firmware8300_firmware8700_firmwarea400_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2019-15217Medium· 4.6An issue was discovered in the Linux kernel before 5.2.3
CVE-2019-20095Medium· 5.5mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handling cases that did not free allocated hostcmd memory, aka CID-003b686ace82
CVE-2019-19054Medium· 4.7A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CI…
CVE-2019-19462Medium· 5.5relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.
CVE-2019-15218Medium· 4.6An issue was discovered in the Linux kernel before 5.1.8
CVE-2019-15219Medium· 4.6An issue was discovered in the Linux kernel before 5.1.8