3.3
CVSSv3

CVE-2018-20855

Published: 26/07/2019 Updated: 20/11/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in the Linux kernel prior to 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

opensuse leap 15.0

opensuse leap 15.1

netapp active iq performance analytics services -

netapp active iq unified manager

netapp data availability services -

netapp element software -

Vendor Advisories

Impact: Moderate Public Date: 2019-07-26 CWE: CWE-200 Bugzilla: 1738708: CVE-2018-20855 kernel: Informa ...