World-writable Permissions in Canonical Cloud-Init Installation
CVE-2024-11584
5.9MEDIUM
What is CVE-2024-11584?
The Canonical Cloud-Init version 25.1.2 contains a vulnerability related to the default permissions set for the systemd socket unit cloud-init-hotplugd.socket. These permissions, set to 0666, allow any user on the system to write to the socket, enabling unprivileged users to execute hotplug-hook commands through the insecure FIFO located at '/run/cloud-init/hook-hotplug-cmd'. This poses a risk of unauthorized access and potential exploitation, making it essential for users to apply the latest updates to mitigate this issue.
Affected Version(s)
cloud-init Linux 21.3 < 25.1.3