CVE-2018-20855: Linux Kernel
Low severity, CVSS 3.3. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.
Affected products
- Linux Linux Kernel: before 4.18.7 (fixed in 4.18.7)
- Netapp Active Iq Performance Analytics Services: affected versions not specified
- Netapp Active Iq Unified Manager: from 9.5
- Netapp Data Availability Services: affected versions not specified
- Netapp Element Software: affected versions not specified
- Opensuse Leap: version 15.0 only; version 15.1 only
Published 2019-07-26. Last modified 2026-06-17.