CVE-2024-11584
published 2025-06-26CVE-2024-11584: cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it…
PriorityP424medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.12%
2.3th percentile
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | < 25.1.3 | 25.1.3 |
| canonical | cloud-init | >= 0 < 22.4.2-1+deb12u3 | 22.4.2-1+deb12u3 |
| canonical | cloud-init | >= 0 < 25.1.4-1 | 25.1.4-1 |
| canonical | cloud-init | >= 0 < 25.1.4-1 | 25.1.4-1 |
| canonical | cloud-init | >= 0 < 25.1.4-0ubuntu0~22.04.1 | 25.1.4-0ubuntu0~22.04.1 |
| canonical | cloud-init | >= 0 < 25.1.4-0ubuntu0~24.04.1 | 25.1.4-0ubuntu0~24.04.1 |
| canonical | cloud-init | >= 0 < 21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2 | 21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2 |
| canonical | cloud-init | >= 0 < 23.1.2-0ubuntu0~18.04.1+esm1 | 23.1.2-0ubuntu0~18.04.1+esm1 |
| canonical | cloud-init | >= 0 < 24.4.1-0ubuntu0~20.04.3+esm1 | 24.4.1-0ubuntu0~20.04.3+esm1 |
| canonical | cloud-init | >= 21.3 < 25.1.3 | 25.1.3 |
| debian | cloud-init | < cloud-init 22.4.2-1+deb12u3 (bookworm) | cloud-init 22.4.2-1+deb12u3 (bookworm) |
| msrc | azl3_cloud-init_24.3.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_cloud-init_24.3.1-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cloud-init_23.3-6_on_cbl_mariner_2.0 | — | — |
| msrc | cm2_cloud-init_23.3-7_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv5.3MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
cloud-init vulnerabilities
vendor_ubuntu·2025-07-28·CVSS 5.9
CVE-2024-6174 [MEDIUM] cloud-init vulnerabilities
Title: cloud-init vulnerabilities
Summary: Several security issues were fixed in cloud-init.
Harry Sintonen discovered that the hotplugd socket in cloud-init was world
writable. An attacker could possibly use this issue to send hotplug-hook
commands. (CVE-2024-11584)
It was discovered that cloud-init granted root access to a hardcoded URL
with a local IP address when a non-x86 platform is detected. An attacker
could possibly impersonate an OpenStack endpoint and provide root
configuration data. (CVE-2024-6174)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cloud-init: Cloud init permissions handling flaw
vendor_redhat·2025-06-26·CVSS 5.9
CVE-2024-11584 [MEDIUM] CWE-276 cloud-init: Cloud init permissions handling flaw
cloud-init: Cloud init permissions handling flaw
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
A default permissions flaw was found in cloud-init. The cloud-init-hotplugd.socket grants 0666 permissions, making it world-writable. This vulnerability allows an unprivileged user to trigger hotplug-hook commands.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Microsoft
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-i
vendor_msrc·2025-06-10·CVSS 5.9
CVE-2024-11584 [MEDIUM] CWE-732 cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-i
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for
Debian
CVE-2024-11584: cloud-init - cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.s...
vendor_debian·2024·CVSS 5.9
CVE-2024-11584 [MEDIUM] CVE-2024-11584: cloud-init - cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.s...
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
Scope: local
bookworm: resolved (fixed in 22.4.2-1+deb12u3)
bullseye: open
forky: resolved (fixed in 25.1.4-1)
sid: resolved (fixed in 25.1.4-1)
trixie: resolved (fixed in 25.1.4-1)
OSV
cloud-init vulnerabilities
osv·2025-07-28·CVSS 5.3
CVE-2024-11584 [MEDIUM] cloud-init vulnerabilities
cloud-init vulnerabilities
Harry Sintonen discovered that the hotplugd socket in cloud-init was world
writable. An attacker could possibly use this issue to send hotplug-hook
commands. (CVE-2024-11584)
It was discovered that cloud-init granted root access to a hardcoded URL
with a local IP address when a non-x86 platform is detected. An attacker
could possibly impersonate an OpenStack endpoint and provide root
configuration data. (CVE-2024-6174)
OSV
CVE-2024-11584: cloud-init through 25
osv·2025-06-26·CVSS 5.3
CVE-2024-11584 [MEDIUM] CVE-2024-11584: cloud-init through 25
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
GHSA
GHSA-3xmh-hrxh-fx8j: cloud-init through 25
ghsa_unreviewed·2025-06-26
CVE-2024-11584 [MEDIUM] CWE-732 GHSA-3xmh-hrxh-fx8j: cloud-init through 25
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This being used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivelege user could trigger hotplug-hook commands.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-26
Published