CVE-2024-11584
26.06.2025, 10:15
cloud-initthrough 25.1.2 includes the systemd socket unitcloud-init-hotplugd.socket with defaultSocketModethat grants 0666 permissions, making it world-writable.This being used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivelege user could triggerhotplug-hook commands.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.

Ubuntu Releases