CVE-2024-11584

Updated on 26 Jun 2025

Severity

5.3 Medium severity

Details

CVSS score
5.3
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Overview

About vulnerability

cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the “/run/cloud-init/hook-hotplug-cmd” FIFO. An unprivileged user could trigger hotplug-hook commands.

Details

Affected product:
AlmaLinux 9.2 ESU
Affected packages:
cloud-init @ 22.1
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the “/run/cloud-init/hook-hotplug-cmd” FIFO. An unprivileged user could trigger hotplug-hook commands.

Fixes