In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
https://security.netapp.com/advisory/ntap-20200204-0002/
https://usn.ubuntu.com/4285-1/
https://usn.ubuntu.com/4287-1/
https://usn.ubuntu.com/4286-2/
https://usn.ubuntu.com/4287-2/
https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
https://usn.ubuntu.com/4284-1/
https://usn.ubuntu.com/4286-1/
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html
Source: MITRE
Published: 2019-12-25
Updated: 2022-03-31
Type: CWE-476
Base Score: 1.9
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 3.4
Severity: LOW
Base Score: 4.7
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 1
Severity: MEDIUM