hw/rdma/vmw/pvrdmacmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in createcqring or createqp_rings.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20125.json"