PT-2019-10283 · Linux+2 · Linux Kernel+2

Publicado

2018-09-17

·

Atualizado

2019-11-20

·

CVE-2018-20855

CVSS v3.1

3.3

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 4.18.7
Description: An issue was discovered in the Linux kernel where mlx5 ib create qp resp was never initialized in create qp common in drivers/infiniband/hw/mlx5/qp.c, resulting in a leak of stack memory to userspace.
Recommendations: For Linux kernel versions prior to 4.18.7, update to version 4.18.7 or later to resolve the issue.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2333
ALT-PU-2018-2336
ALT-PU-2019-1433
CVE-2018-20855
OPENSUSE-SU-2019:1923-1
OPENSUSE-SU-2019:1924-1
OPENSUSE-SU-2019_1923-1
OPENSUSE-SU-2019_1924-1
SUSE-SU-2019:14157-1
SUSE-SU-2019:2068-1
SUSE-SU-2019:2069-1
SUSE-SU-2019:2070-1
SUSE-SU-2019:2071-1
SUSE-SU-2019:2072-1
SUSE-SU-2019:2073-1
SUSE-SU-2019:2262-1
SUSE-SU-2019:2263-1
SUSE-SU-2019:2299-1
SUSE-SU-2019:2430-1
SUSE-SU-2019:2450-1
SUSE-SU-2019_14157-1
SUSE-SU-2019_2068-1
SUSE-SU-2019_2070-1
SUSE-SU-2019_2071-1
SUSE-SU-2019_2072-1
SUSE-SU-2019_2073-1
SUSE-SU-2019_2262-1

Produtos afetados

Alt Linux
Linux Kernel
Suse