In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
[
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@f70267f379b5e5e11bdc5d72a56bf17e5feed01f",
"id": "CVE-2019-19965-c61cf92b",
"target": {
"file": "drivers/scsi/libsas/sas_discover.c"
},
"digest": {
"line_hashes": [
"159825309603133828253105138588693101438",
"48678089467837017227818457111317683831",
"182889339025171609399503108031216287065",
"167510991992306750406675609564470442543",
"70481715336734230877425023154250102831",
"313475509728310704566782346088071179400",
"166018590061794355484308125195768287138",
"134017343553699360269638419376951778799",
"246644992822862457293955856875209287109"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@f70267f379b5e5e11bdc5d72a56bf17e5feed01f",
"id": "CVE-2019-19965-fddd2fbf",
"target": {
"file": "drivers/scsi/libsas/sas_discover.c",
"function": "sas_get_port_device"
},
"digest": {
"function_hash": "177862076400940715972692576611150921520",
"length": 2964.0
},
"signature_type": "Function",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19965.json"