CVE-2024-11584
26.06.2025, 10:15
cloud-initthrough 25.1.2 includes the systemd socket unitcloud-init-hotplugd.socket with defaultSocketModethat grants 0666 permissions, making it world-writable.This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could triggerhotplug-hook commands.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | cloud-init | 𝑥 < 25.1.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration