CVE-2024-6174
published 2025-06-26CVE-2024-6174: When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default…
PriorityP346high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.20%
10.4th percentile
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | cloud-init | < 25.1.3 | 25.1.3 |
| canonical | cloud-init | >= 0 < 22.4.2-1+deb12u3 | 22.4.2-1+deb12u3 |
| canonical | cloud-init | >= 0 < 25.1.4-1 | 25.1.4-1 |
| canonical | cloud-init | >= 0 < 25.1.4-1 | 25.1.4-1 |
| canonical | cloud-init | >= 0 < 25.1.4-0ubuntu0~22.04.1 | 25.1.4-0ubuntu0~22.04.1 |
| canonical | cloud-init | >= 0 < 25.1.4-0ubuntu0~24.04.1 | 25.1.4-0ubuntu0~24.04.1 |
| canonical | cloud-init | >= 0 < 21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2 | 21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2 |
| canonical | cloud-init | >= 0 < 23.1.2-0ubuntu0~18.04.1+esm1 | 23.1.2-0ubuntu0~18.04.1+esm1 |
| canonical | cloud-init | >= 0 < 24.4.1-0ubuntu0~20.04.3+esm1 | 24.4.1-0ubuntu0~20.04.3+esm1 |
| canonical | cloud-init | >= 0.7.9 < 25.1.3 | 25.1.3 |
| debian | cloud-init | < cloud-init 22.4.2-1+deb12u3 (bookworm) | cloud-init 22.4.2-1+deb12u3 (bookworm) |
| msrc | azl3_cloud-init_24.3.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_cloud-init_24.3.1-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cloud-init_23.3-6_on_cbl_mariner_2.0 | — | — |
| msrc | cm2_cloud-init_23.3-7_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
cloud-init vulnerabilities
vendor_ubuntu·2025-07-28·CVSS 5.9
CVE-2024-6174 [MEDIUM] cloud-init vulnerabilities
Title: cloud-init vulnerabilities
Summary: Several security issues were fixed in cloud-init.
Harry Sintonen discovered that the hotplugd socket in cloud-init was world
writable. An attacker could possibly use this issue to send hotplug-hook
commands. (CVE-2024-11584)
It was discovered that cloud-init granted root access to a hardcoded URL
with a local IP address when a non-x86 platform is detected. An attacker
could possibly impersonate an OpenStack endpoint and provide root
configuration data. (CVE-2024-6174)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cloud-init: Cloud init permissions flaw
vendor_redhat·2025-06-26·CVSS 8.8
CVE-2024-6174 [HIGH] CWE-276 cloud-init: Cloud init permissions flaw
cloud-init: Cloud init permissions flaw
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
An access permissions flaw was found in cloud-init. When a non-x86 platform is detected, cloud-init grants root access to a hardcoded URL with a local IP address, which creates a security exposure.
Statement: This vulnerability is Important rather than Moderate because it directly impacts the security boundary between a system’s local environment and potentially untrusted network metadata sources. On non-x86 platforms, the fallback to platform enumeration with default datasource scanning could allow cloud-init to treat a malicious or spoofed local metadata se
Microsoft
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
vendor_msrc·2025-06-10·CVSS 8.8
CVE-2024-6174 [HIGH] CWE-287 When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to r
Debian
CVE-2024-6174: cloud-init - When a non-x86 platform is detected, cloud-init grants root access to a hardcode...
vendor_debian·2024·CVSS 8.8
CVE-2024-6174 [HIGH] CVE-2024-6174: cloud-init - When a non-x86 platform is detected, cloud-init grants root access to a hardcode...
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
Scope: local
bookworm: resolved (fixed in 22.4.2-1+deb12u3)
bullseye: open
forky: resolved (fixed in 25.1.4-1)
sid: resolved (fixed in 25.1.4-1)
trixie: resolved (fixed in 25.1.4-1)
OSV
cloud-init vulnerabilities
osv·2025-07-28·CVSS 5.3
CVE-2024-11584 [MEDIUM] cloud-init vulnerabilities
cloud-init vulnerabilities
Harry Sintonen discovered that the hotplugd socket in cloud-init was world
writable. An attacker could possibly use this issue to send hotplug-hook
commands. (CVE-2024-11584)
It was discovered that cloud-init granted root access to a hardcoded URL
with a local IP address when a non-x86 platform is detected. An attacker
could possibly impersonate an OpenStack endpoint and provide root
configuration data. (CVE-2024-6174)
OSV
CVE-2024-6174: When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address
osv·2025-06-26·CVSS 8.8
CVE-2024-6174 [HIGH] CVE-2024-6174: When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
GHSA
GHSA-w8g9-wp36-fchj: When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address
ghsa_unreviewed·2025-06-26
CVE-2024-6174 [HIGH] CWE-287 GHSA-w8g9-wp36-fchj: When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-06-26
Published