Disclosure summary
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
Source-reported weakness categories
CWE-476
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2019-19965
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| linux | linux_kernel | * {"versionEndIncluding":"5.4.6"} |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.10 |
| netapp | active_iq_unified_manager | - |
| netapp | cloud_backup | - |
| netapp | data_availability_services | - |
| netapp | e-series_santricity_os_controller | * {"versionStartIncluding":"11.0.0","versionEndIncluding":"11.70.1"} |
| netapp | hci_management_node | - |
| netapp | solidfire | - |
| netapp | steelstore_cloud_integrated_storage | - |
| opensuse | leap | 15.1 |
| netapp | a700s_firmware | - |
| netapp | h610s_firmware | - |
| netapp | 8300_firmware | - |
| netapp | 8700_firmware | - |
| netapp | a400_firmware | - |
Original records & references
- NIST NVD record
- CVE Program record
- git.kernel.org — Exploit, Patch, Vendor Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- security.netapp.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- git.kernel.org — Exploit, Patch, Vendor Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- security.netapp.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
- usn.ubuntu.com — Third Party Advisory
PUBLISHED 2019-12-24T23:15:12-05:00
MODIFIED 2026-10-08T17:17:19-04:00
INGESTED 2026-10-10T20:50:19-04:00