CVE-2018-20855
published 2019-07-26CVE-2018-20855: An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.46%
36.5th percentile
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.18.8-1 (bookworm) | linux 4.18.8-1 (bookworm) |
| linux | linux_kernel | < 4.18.7 | 4.18.7 |
| linux | linux_kernel | >= 0 < 4.18.8-1 | 4.18.8-1 |
| linux | linux_kernel | >= 0 < 4.18.8-1 | 4.18.8-1 |
| linux | linux_kernel | >= 0 < 4.18.8-1 | 4.18.8-1 |
| linux | linux_kernel | >= 0 < 4.18.8-1 | 4.18.8-1 |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xr6p-4wfc-3fxp: An issue was discovered in the Linux kernel before 4
ghsa_unreviewed·2022-05-24
CVE-2018-20855 [LOW] GHSA-xr6p-4wfc-3fxp: An issue was discovered in the Linux kernel before 4
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.
OSV
CVE-2018-20855: An issue was discovered in the Linux kernel before 4
osv·2019-07-26·CVSS 3.3
CVE-2018-20855 [LOW] CVE-2018-20855: An issue was discovered in the Linux kernel before 4
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.
Red Hat
kernel: Information leak in create_qp_common in drivers/infiniband/hw/mlx5/qp.c
vendor_redhat·2019-07-26·CVSS 3.3
CVE-2018-20855 [LOW] CWE-200 kernel: Information leak in create_qp_common in drivers/infiniband/hw/mlx5/qp.c
kernel: Information leak in create_qp_common in drivers/infiniband/hw/mlx5/qp.c
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.
A flaw was discovered in the Linux kernel's implementation of InfiniBand. A local attacker who is able to execute a read from the InfiniBand device could trigger an information leak of kernel memory to userspace which can be used to further attack the system.
Mitigation: If the InfiniBand device is in use, there is no known mitigation for this flaw. If the InfiniBand device is not in use, the kernel module (mlx5_ib) can be blacklisted and unloaded.
Package: kernel (Red Hat Enterprise Linux 5) - Not a
Debian
CVE-2018-20855: linux - An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common i...
vendor_debian·2018·CVSS 3.3
CVE-2018-20855 [LOW] CVE-2018-20855: linux - An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common i...
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.
Scope: local
bookworm: resolved (fixed in 4.18.8-1)
bullseye: resolved (fixed in 4.18.8-1)
forky: resolved (fixed in 4.18.8-1)
sid: resolved (fixed in 4.18.8-1)
trixie: resolved (fixed in 4.18.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-20855 kernel: Information leak in create_qp_common in drivers/infiniband/hw/mlx5/qp.c
bugzilla·2019-08-07·CVSS 3.3
CVE-2018-20855 [LOW] CVE-2018-20855 kernel: Information leak in create_qp_common in drivers/infiniband/hw/mlx5/qp.c
CVE-2018-20855 kernel: Information leak in create_qp_common in drivers/infiniband/hw/mlx5/qp.c
A flaw was discovered in the Linux kernels implementation of infiniband for MLX5. A local attacker who is able to execute a read from the infiband device could trigger an information leak of kernel memory to userspace which can be used to further attack the system.
Additional Information:
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.7
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0625b4ba1a5d4703c7fb01c497bd6c156908af00
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1738709]
---
This was fixed in Fedora with the 4.18.7 stable kernel update.
---
Mitigation:
If the InfiniBand device is in use, there is no know
Bugzilla
CVE-2018-20855 kernel: Information leak in create_qp_common in drivers/infiniband/hw/mlx5/qp.c [fedora-all]
bugzilla·2019-08-07·CVSS 3.3
CVE-2018-20855 [LOW] CVE-2018-20855 kernel: Information leak in create_qp_common in drivers/infiniband/hw/mlx5/qp.c [fedora-all]
CVE-2018-20855 kernel: Information leak in create_qp_common in drivers/infiniband/hw/mlx5/qp.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00056.htmlhttps://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.7https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0625b4ba1a5d4703c7fb01c497bd6c156908af00https://github.com/torvalds/linux/commit/0625b4ba1a5d4703c7fb01c497bd6c156908af00https://security.netapp.com/advisory/ntap-20190905-0002/http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00055.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00056.htmlhttps://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.18.7https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0625b4ba1a5d4703c7fb01c497bd6c156908af00https://github.com/torvalds/linux/commit/0625b4ba1a5d4703c7fb01c497bd6c156908af00https://security.netapp.com/advisory/ntap-20190905-0002/
2019-07-26
Published