First published: Wed Dec 25 2019(Updated: )
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <=5.4.6 | |
Debian GNU/Linux | =8.0 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.10 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp cloud backup | ||
netapp data availability services | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.70.1 | |
netapp hci management node | ||
netapp solidfire | ||
NetApp SteelStore | ||
openSUSE | =15.1 | |
All of | ||
NetApp AFF A700s Firmware | ||
netapp a700s | ||
All of | ||
netapp h610s firmware | ||
netapp h610s | ||
All of | ||
NetApp AFF 8300 Firmware | ||
NetApp FAS8300 | ||
All of | ||
NetApp AFF 8700 Firmware | ||
NetApp FAS8700 | ||
All of | ||
NetApp AFF A400 Firmware | ||
NetApp FAS A400 | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.13-1 | |
Debian | =8.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.10 | |
NetApp AFF A700s Firmware | ||
netapp a700s | ||
netapp h610s firmware | ||
netapp h610s | ||
NetApp AFF 8300 Firmware | ||
NetApp FAS8300 | ||
NetApp AFF 8700 Firmware | ||
NetApp FAS8700 | ||
NetApp AFF A400 Firmware | ||
NetApp FAS A400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19965 is classified as a high severity vulnerability due to a NULL pointer dereference that can lead to system crashes.
To fix CVE-2019-19965, update your Linux kernel to version 5.10.223-1 or later as specified in the security patches.
CVE-2019-19965 affects all Linux kernel versions up to and including 5.4.6.
CVE-2019-19965 is a NULL pointer dereference vulnerability that occurs during port disconnection handling in the Linux kernel.
Yes, CVE-2019-19965 affects various distributions, including Debian 8.0 and Ubuntu versions 14.04, 16.04, 18.04, and 19.10.