REDHAT-BUG-2374924: High severity cloud-init cloud-init vulnerability
Published Jun 26, 2025
·Updated
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
Affected Software
1 affected component
cloud-init cloud-init
Event History
Jun 26, 2025
Data Sourced
via Red Hat·10:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2374924?
The severity of REDHAT-BUG-2374924 is considered significant due to the unauthorized root access granted to a hardcoded URL.
2
How do I fix REDHAT-BUG-2374924?
To fix REDHAT-BUG-2374924, ensure that cloud-init default configurations are properly set to disable platform enumeration.
3
What platforms are affected by REDHAT-BUG-2374924?
REDHAT-BUG-2374924 affects non-x86 platforms that use cloud-init.
4
Is there a workaround for REDHAT-BUG-2374924?
A potential workaround for REDHAT-BUG-2374924 is to manually configure cloud-init to restrict access to the hardcoded URL.
5
When was REDHAT-BUG-2374924 reported?
REDHAT-BUG-2374924 was reported in relation to issues with cloud-init configurations for non-x86 platforms.