CVE-2024-11584
26.06.2025, 10:15
cloud-initthrough 25.1.2 includes the systemd socket unitcloud-init-hotplugd.socket with defaultSocketModethat grants 0666 permissions, making it world-writable.This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could triggerhotplug-hook commands.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | cloud-init | 𝑥 < 25.1.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration