An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2019-07-26 05:15
Updated : 2024-11-21 04:02
NVD link : CVE-2018-20855
Mitre link : CVE-2018-20855
CVE.ORG link : CVE-2018-20855
JSON object : View
Products Affected
netapp
- active_iq_unified_manager
- data_availability_services
- active_iq_performance_analytics_services
- element_software
linux
- linux_kernel
opensuse
- leap
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer