Unrated severityNVD Advisory· Published Jun 26, 2025· Updated Jun 26, 2025
CVE-2024-11584
CVE-2024-11584
Description
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
Affected products
2- Range: <=25.1.2
- Canonical/cloud-initv5Range: 21.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.