vulnerability
Ubuntu: USN-7677-1 (CVE-2024-11584): cloud-init vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:L/AC:L/Au:N/C:P/I:P/A:P) | Jun 26, 2025 | Jul 1, 2025 | Apr 16, 2026 |
Severity
5
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
Published
Jun 26, 2025
Added
Jul 1, 2025
Modified
Apr 16, 2026
Description
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
Solutions
ubuntu-pro-upgrade-cloud-initubuntu-upgrade-cloud-initubuntu-upgrade-cloud-init-base
References
- CVE-2024-11584
- https://attackerkb.com/topics/CVE-2024-11584
- CWE-732
- EUVD-EUVD-2024-54980
- UBUNTU-USN-7677-1
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-54980
- https://github.com/canonical/cloud-init/pull/6265/commits/6e10240a7f0a2d6110b398640b3fd46cfa9a7cf3
- https://github.com/canonical/cloud-init/releases/tag/25.1.3
- https://www.cve.org/CVERecord?id=CVE-2024-11584
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.