CVE-2024-6174: High severity Canonical cloud-init vulnerability
Published Jun 26, 2025
·Updated
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
Affected Software
2 affected components
Canonical cloud-init
Canonical cloud-init<25.1.3
Event History
Jun 26, 2025
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverity
Data Sourced
via Red Hat·10:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6174?
CVE-2024-6174 has a high severity rating due to the risk of unauthorized root access.
2
How do I fix CVE-2024-6174?
To fix CVE-2024-6174, upgrade to the latest version of cloud-init where the vulnerability has been patched.
3
What platforms are affected by CVE-2024-6174?
CVE-2024-6174 affects non-x86 platforms running cloud-init.
4
What are the potential risks of CVE-2024-6174?
The risks include unauthorized access to the system, which could lead to data breaches or system compromise.
5
What mitigation measures can be taken for CVE-2024-6174 before a patch is applied?
As a mitigation measure, ensure that platform enumeration is disabled in your cloud-init configuration.