Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20855

Опубликовано: 26 июл. 2019
Источник: nvd
CVSS3: 3.3
CVSS2: 2.1
EPSS Низкий

Описание

An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Версия до 4.18.7 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:netapp:active_iq_performance_analytics_services:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*
Версия от 9.5 (включая)
cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*

EPSS

Процентиль: 29%
0.00102
Низкий

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 3.3
ubuntu
почти 6 лет назад

An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

CVSS3: 3.3
redhat
почти 6 лет назад

An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

CVSS3: 3.3
debian
почти 6 лет назад

An issue was discovered in the Linux kernel before 4.18.7. In create_q ...

github
около 3 лет назад

An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.

suse-cvrf
почти 6 лет назад

Security update for the Linux Kernel

EPSS

Процентиль: 29%
0.00102
Низкий

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-119