stable

cloud-init-24.2-4.fc41

FEDORA-2025-58f05c43ae created by jcline a year ago for Fedora 41

Backport fixes for CVE-2024-6174 and CVE-2024-11584

  • cloud-init included the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. An unprivelege user could trigger hotplug-hook commands (CVE-2024-11584)

  • When a non-x86 platform is detected, cloud-init granted root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration (CVE-2024-6174)

Note that the fix for CVE-2024-6174 includes a change that may break non-x86 OpenStack Nova users. Affected users may wish to use ConfigDrive as a workaround

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2025-58f05c43ae

This update has been submitted for testing by jcline.

a year ago

This update's test gating status has been changed to 'ignored'.

a year ago

This update has been pushed to testing.

a year ago

This update has been submitted for stable by bodhi.

a year ago

This update has been pushed to stable.

a year ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
7 days
Dates
submitted
a year ago
in testing
a year ago
in stable
a year ago
approved
a year ago
BZ#2375012 CVE-2024-6174 cloud-init: From CVEorg collector [fedora-41]
0
0
BZ#2375013 CVE-2024-6174 cloud-init: From CVEorg collector [fedora-42]
0
0
BZ#2375025 CVE-2024-11584 cloud-init: From CVEorg collector [fedora-41]
0
0
BZ#2375026 CVE-2024-11584 cloud-init: From CVEorg collector [fedora-42]
0
0

Automated Test Results