CRITICAL 9.8 Microsoft
CVE-2024-53094
RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES
Microsoft Security Update 2024-Nov: RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES
Affected Products
- azl3 kernel 6.6.64.2-1 on Azure Linux 3.0
- azl3 kernel 6.6.57.1-7 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-53094
- https://nvd.nist.gov/vuln/detail/CVE-2024-53094
This critical severity vulnerability with a CVSS score of 9.8 was published on 2024-11-12 via Microsoft. Affected: azl3 kernel 6.6.64.2-1 on Azure Linux 3.0, azl3 kernel 6.6.57.1-7 on Azure Linux 3.0.
Risk Timeline
CVE Disclosed2024-11-12 · 691 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-53094NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2024-53094Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2024-56719 | net: stmmac: fix TSO DMA API usage causing oops | CRITICAL | 10.0 |
| CVE-2025-68121 | Unexpected session resumption in crypto/tls | CRITICAL | 10.0 |
| CVE-2026-27211 | Cloud Hypervisor: Host File Exfiltration via QCOW Backing File Abuse | CRITICAL | 10.0 |
| CVE-2025-37879 | 9p/net: fix improper handling of bogus negative read/write replies | CRITICAL | 9.8 |
| CVE-2024-41184 | In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3. | CRITICAL | 9.8 |
| CVE-2024-6611 | A nested iframe, triggering a cross-site navigation, could send SameSite=Strict | CRITICAL | 9.8 |
vulnfeed aggregates 7640 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.