World-writable Permissions in Canonical Cloud-Init Installation
CVE-2024-11584
What is CVE-2024-11584?
The Canonical Cloud-Init version 25.1.2 contains a vulnerability related to the default permissions set for the systemd socket unit cloud-init-hotplugd.socket. These permissions, set to 0666, allow any user on the system to write to the socket, enabling unprivileged users to execute hotplug-hook commands through the insecure FIFO located at '/run/cloud-init/hook-hotplug-cmd'. This poses a risk of unauthorized access and potential exploitation, making it essential for users to apply the latest updates to mitigate this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cloud-init Linux 21.3 < 25.1.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
