Vulnerability Description
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 4.18.7 |
| Opensuse | Leap | 15.0 |
| Netapp | Active Iq Performance Analytics Services | - |
| Netapp | Active Iq Unified Manager | >= 9.5 |
| Netapp | Data Availability Services | - |
| Netapp | Element Software | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00055.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00056.htmlThird Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.7Mailing ListRelease NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0625bMailing ListPatchVendor Advisory
- https://github.com/torvalds/linux/commit/0625b4ba1a5d4703c7fb01c497bd6c156908af0PatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190905-0002/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00055.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00056.htmlThird Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.7Mailing ListRelease NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0625bMailing ListPatchVendor Advisory
- https://github.com/torvalds/linux/commit/0625b4ba1a5d4703c7fb01c497bd6c156908af0PatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190905-0002/Third Party Advisory
FAQ
What is CVE-2018-20855?
CVE-2018-20855 is a vulnerability with a CVSS score of 3.3 (LOW). An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to ...
How severe is CVE-2018-20855?
CVE-2018-20855 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20855?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Opensuse Leap, Netapp Active Iq Performance Analytics Services, Netapp Active Iq Unified Manager, Netapp Data Availability Services.