[SECURITY] Fedora 41 Update: cloud-init-24.2-4.fc41

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-58f05c43ae
2025-07-30 01:28:52.274692+00:00
--------------------------------------------------------------------------------

Name        : cloud-init
Product     : Fedora 41
Version     : 24.2
Release     : 4.fc41
URL         : https://github.com/canonical/cloud-init
Summary     : Cloud instance init scripts
Description :
Cloud-init is a set of init scripts for cloud instances.  Cloud instances
need special scripts to run during initialization to retrieve and install
ssh keys and to let the user run various scripts.

--------------------------------------------------------------------------------
Update Information:

Backport fixes for CVE-2024-6174 and CVE-2024-11584
cloud-init included the systemd socket unit cloud-init-hotplugd.socket with
default SocketMode that grants 0666 permissions, making it world-writable. An
unprivelege user could trigger hotplug-hook commands (CVE-2024-11584)
When a non-x86 platform is detected, cloud-init granted root access to a
hardcoded url with a local IP address. To prevent this, cloud-init default
configurations disable platform enumeration (CVE-2024-6174)
Note that the fix for CVE-2024-6174 includes a change that may break non-x86
OpenStack Nova users. Affected users may wish to use ConfigDrive as a workaround
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 21 2025 Jeremy Cline <jeremycline@xxxxxxxxxxxxxxxxxxx> - 24.2-4
- Backport fixes for CVE-2024-6174 and CVE-2024-11584
- cloud-init included the systemd socket unit cloud-init-hotplugd.socket
  with default SocketMode that grants 0666 permissions, making it world-
  writable. An unprivelege user could trigger hotplug-hook commands
  (CVE-2024-11584)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2375012 - CVE-2024-6174 cloud-init: From CVEorg collector [fedora-41]
        https://bugzilla.redhat.com/show_bug.cgi?id=2375012
  [ 2 ] Bug #2375013 - CVE-2024-6174 cloud-init: From CVEorg collector [fedora-42]
        https://bugzilla.redhat.com/show_bug.cgi?id=2375013
  [ 3 ] Bug #2375025 - CVE-2024-11584 cloud-init: From CVEorg collector [fedora-41]
        https://bugzilla.redhat.com/show_bug.cgi?id=2375025
  [ 4 ] Bug #2375026 - CVE-2024-11584 cloud-init: From CVEorg collector [fedora-42]
        https://bugzilla.redhat.com/show_bug.cgi?id=2375026
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-58f05c43ae' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
package-announce mailing list -- package-announce@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to package-announce-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue




[Index of Archives]     [Fedora Users]     [Fedora Legacy]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [Yosemite Photos]     [KDE Users]

  Powered by Linux