An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
https://usn.ubuntu.com/4287-2/
https://usn.ubuntu.com/4287-1/
https://usn.ubuntu.com/4284-1/
https://usn.ubuntu.com/4258-1/
https://usn.ubuntu.com/4254-2/
https://usn.ubuntu.com/4254-1/
https://syzkaller.appspot.com/bug?id=c0203bd72037d07493f4b7562411e4f5f4553a8f
https://security.netapp.com/advisory/ntap-20190905-0002/
https://seclists.org/bugtraq/2020/Jan/10
https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
http://www.openwall.com/lists/oss-security/2019/08/22/1
http://www.openwall.com/lists/oss-security/2019/08/20/2
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00037.html
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00036.html