An issue was discovered in the Linux kernel before 4.18.7. In createqpcommon in drivers/infiniband/hw/mlx5/qp.c, mlx5ibcreateqpresp was never initialized, resulting in a leak of stack memory to userspace.
[
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0625b4ba1a5d4703c7fb01c497bd6c156908af00",
"id": "CVE-2018-20855-105985b6",
"target": {
"file": "drivers/infiniband/hw/mlx5/qp.c",
"function": "create_qp_common"
},
"digest": {
"function_hash": "219547066054709028932650485581368459705",
"length": 10027.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@0625b4ba1a5d4703c7fb01c497bd6c156908af00",
"id": "CVE-2018-20855-d3756b4e",
"target": {
"file": "drivers/infiniband/hw/mlx5/qp.c"
},
"digest": {
"line_hashes": [
"240960463148056473952389103157777032472",
"193926880387724528851132880587337385282",
"268494031685249036547418746770765218874",
"196178004458180149215246532108954362870"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20855.json"
[
{
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/0625b4ba1a5d4703c7fb01c497bd6c156908af00",
"id": "CVE-2018-20855-3a5afbcf",
"target": {
"file": "drivers/infiniband/hw/mlx5/qp.c",
"function": "create_qp_common"
},
"digest": {
"function_hash": "219547066054709028932650485581368459705",
"length": 10027.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/0625b4ba1a5d4703c7fb01c497bd6c156908af00",
"id": "CVE-2018-20855-3f1600d7",
"target": {
"file": "drivers/infiniband/hw/mlx5/qp.c"
},
"digest": {
"line_hashes": [
"240960463148056473952389103157777032472",
"193926880387724528851132880587337385282",
"268494031685249036547418746770765218874",
"196178004458180149215246532108954362870"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20855.json"