PT-2019-10283 · Linux+2 · Linux Kernel+2

Published

2018-09-17

·

Updated

2019-11-20

·

CVE-2018-20855

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 4.18.7
Description: An issue was discovered in the Linux kernel where mlx5 ib create qp resp was never initialized in create qp common in drivers/infiniband/hw/mlx5/qp.c, resulting in a leak of stack memory to userspace.
Recommendations: For Linux kernel versions prior to 4.18.7, update to version 4.18.7 or later to resolve the issue.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2333
ALT-PU-2018-2336
ALT-PU-2019-1433
CVE-2018-20855
OPENSUSE-SU-2019:1923-1
OPENSUSE-SU-2019:1924-1
OPENSUSE-SU-2019_1923-1
OPENSUSE-SU-2019_1924-1
SUSE-SU-2019:14157-1
SUSE-SU-2019:2068-1
SUSE-SU-2019:2069-1
SUSE-SU-2019:2070-1
SUSE-SU-2019:2071-1
SUSE-SU-2019:2072-1
SUSE-SU-2019:2073-1
SUSE-SU-2019:2262-1
SUSE-SU-2019:2263-1
SUSE-SU-2019:2299-1
SUSE-SU-2019:2430-1
SUSE-SU-2019:2450-1
SUSE-SU-2019_14157-1
SUSE-SU-2019_2068-1
SUSE-SU-2019_2070-1
SUSE-SU-2019_2071-1
SUSE-SU-2019_2072-1
SUSE-SU-2019_2073-1
SUSE-SU-2019_2262-1

Affected Products

Alt Linux
Linux Kernel
Suse