imPC@ndo IT

Tracker / CVE-2018-20855

CVE-2018-20855

Low 3.3

An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

Affected products and versions

linux linux_kernel · … → 4.18.7
netapp active_iq_performance_analytics_services
netapp active_iq_unified_manager · 9.5 → …
netapp data_availability_services
netapp element_software
opensuse leap

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References