CVE-2018-20855: Linux Kernel

Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

Affected products

  • Linux Linux Kernel: before 4.18.7 (fixed in 4.18.7)
  • Netapp Active Iq Performance Analytics Services: affected versions not specified
  • Netapp Active Iq Unified Manager: from 9.5
  • Netapp Data Availability Services: affected versions not specified
  • Netapp Element Software: affected versions not specified
  • Opensuse Leap: version 15.0 only; version 15.1 only

Published 2019-07-26. Last modified 2026-06-17.