CVE-2024-6174

Updated: 2025-08-29 16:01:10.802263

Description:

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 8.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU cloud-init 22.1 8.8 HIGH Released CLSA-2025:1760018787 2025-10-09 15:54:02