CVE-2018-20855 REJECTED

An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

EPSS 0.11% · 29.2th percentile

Risk Scores

EPSS Score
0.11%
29.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-hwe0
Ubuntu:16.04:LTSlinux0
Ubuntu:16.04:LTSlinux-oracle0
Ubuntu:18.04:LTSlinux-oem0
Ubuntu:18.04:LTSlinux-azure0
Ubuntu:16.04:LTSlinux-kvm0
Ubuntu:16.04:LTSlinux-aws-hwe0
Ubuntu:16.04:LTSlinux-hwe0
Ubuntu:18.04:LTSlinux-aws0
Ubuntu:18.04:LTSlinux-gke-4.150
Ubuntu:16.04:LTSlinux-raspi20
Ubuntu:16.04:LTSlinux-azure0
Ubuntu:16.04:LTSlinux-gcp0
Ubuntu:18.04:LTSlinux-snapdragon0
Ubuntu:16.04:LTSlinux-snapdragon0
Ubuntu:18.04:LTSlinux-gcp-edge0
Ubuntu:18.04:LTSlinux-hwe-edge0
Ubuntu:18.04:LTSlinux-gcp0
Ubuntu:16.04:LTSlinux-aws0
Ubuntu:18.04:LTSlinux-oracle0

…and 3 more

Timeline

References

Open in Interactive Console →