CVE-2019-19965: Null Pointer Dereference
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sasdiscover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 5.4.6Patch CID-f70267f379b5 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch CID-f70267f379b5
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19965?
CVE-2019-19965 is classified as a high severity vulnerability due to a NULL pointer dereference that can lead to system crashes.
How do I fix CVE-2019-19965?
To fix CVE-2019-19965, update your Linux kernel to version 5.10.223-1 or later as specified in the security patches.
Which Linux kernel versions are affected by CVE-2019-19965?
CVE-2019-19965 affects all Linux kernel versions up to and including 5.4.6.
What type of vulnerability is CVE-2019-19965?
CVE-2019-19965 is a NULL pointer dereference vulnerability that occurs during port disconnection handling in the Linux kernel.
Are there any specific distributions affected by CVE-2019-19965?
Yes, CVE-2019-19965 affects various distributions, including Debian 8.0 and Ubuntu versions 14.04, 16.04, 18.04, and 19.10.