---
id: CVE-2019-19965
title: >-
  In the Linux kernel through 5.4.6, there is a NULL pointer dereference in
  drivers/scsi/libsas/sas_discover.c because of mishandling of port
  disconnection during discovery, related to a PHY down race condition, aka
  CID-f70267f379b5.
summary: >-
  In the Linux kernel through 5.4.6, there is a NULL pointer dereference in
  drivers/scsi/libsas/sas_discover.c because of mishandling of port
  disconnection during discovery, related to a PHY down race condition, aka
  CID-f70267f379b5.
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: netapp
product: active_iq_unified_manager
affected:
  - linux_kernel <= 5.4.6
  - debian_linux = 8.0
  - ubuntu_linux = 14.04
  - ubuntu_linux = 16.04
  - ubuntu_linux = 18.04
  - ubuntu_linux = 19.10
  - active_iq_unified_manager
  - cloud_backup
  - data_availability_services
  - 'e-series_santricity_os_controller >= 11.0.0, <= 11.70.1'
  - hci_management_node
  - solidfire
  - steelstore_cloud_integrated_storage
  - leap = 15.1
  - a700s_firmware
  - h610s_firmware
  - 8300_firmware
  - 8700_firmware
  - a400_firmware
published: '2019-12-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:19.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-19965'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html'
    label: cve@mitre.org
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f70267f379b5e5e11bdc5d72a56bf17e5feed01f
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20200204-0002/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4284-1/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4285-1/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4286-1/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4286-2/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4287-1/'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4287-2/'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f70267f379b5e5e11bdc5d72a56bf17e5feed01f
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20200204-0002/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4284-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4285-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4286-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4286-2/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4287-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4287-2/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00654
epssPercentile: 0.49751
ingestedAt: '2026-10-08T22:11:53.709Z'
---

## Overview

In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.

## Affected

- `linux_kernel <= 5.4.6`
- `debian_linux = 8.0`
- `ubuntu_linux = 14.04`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 18.04`
- `ubuntu_linux = 19.10`
- `active_iq_unified_manager`
- `cloud_backup`
- `data_availability_services`
- `e-series_santricity_os_controller >= 11.0.0, <= 11.70.1`
- `hci_management_node`
- `solidfire`
- `steelstore_cloud_integrated_storage`
- `leap = 15.1`
- `a700s_firmware`
- `h610s_firmware`
- `8300_firmware`
- `8700_firmware`
- `a400_firmware`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
