CVE-2018-20871 does not apply to the gridengine package in Debian
Had a quick look at this.
This CVE talks about Unica Grid Engine, not son of grid engine. These are both different forks of the original sun grid engine that was abandoned by oracle after the sun acquisition.
The CVE mentions that it only happens when the docker mode is enabled in Univa grid engine, a feature that does not exist in son of grid engine, and must therefore be code unique to the Univa fork.
I therefore think it can be closed gf safely as not applying to Debian.
I'd do an MR, but I'm on mobile and due to file sizes it's not possible to exit this through the webinterface, so...