CVE-2024-6174
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-6174 is a permissions and authentication flaw in Canonical's cloud-init tool where, upon detecting a non-x86 platform, cloud-init incorrectly grants root access to a hardcoded URL with a local IP address. This behavior is classified under CWE-276 (Incorrect Default Permissions) and CWE-287 (Improper Authentication). All versions of cloud-init prior to 25.1.3 are affected (versions 0.7.9 through <25.1.3). The vulnerability was publicly disclosed on June 26, 2025, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is that cloud-init, when it identifies a non-x86 platform (e.g., ARM, s390x, or other architectures), attempts to enumerate the platform type and in doing so grants root-level access to a hardcoded local IP address URL — likely a metadata service endpoint — without proper authentication controls (CWE-276, CWE-287). To mitigate this by default, cloud-init's default configuration disables platform enumeration, meaning systems using non-default configurations or explicitly enabling platform enumeration on non-x86 hardware are at risk. The attack vector is adjacent network (AV:A), requiring no privileges or user interaction, making it exploitable by any attacker on the same network segment. The fix in version 25.1.3 prevents cloud-init from attempting to identify non-x86 OpenStack instances, eliminating the unsafe access grant (cloud-init Release 25.1.3, Red Hat Bugzilla).

Impact

Successful exploitation allows an adjacent network attacker to gain root-level access to the affected cloud instance without any credentials or user interaction, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive data, modify system configurations, install malware, or disrupt services on the compromised host. The vulnerability is particularly relevant in cloud and virtualized environments running non-x86 architectures (e.g., ARM-based or IBM Z cloud instances) where cloud-init is widely deployed for instance initialization (Red Hat Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit code known at this time, and no evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.016% (0.000160), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. The vulnerability is detectable by multiple commercial scanners including Qualys and Nessus (Red Hat Advisory).

Exploitation steps

  1. Reconnaissance: Identify cloud instances running on non-x86 architectures (ARM, s390x, POWER, etc.) that use cloud-init versions prior to 25.1.3, particularly in environments where platform enumeration may be enabled.
  2. Network positioning: Gain access to the same adjacent network segment as the target instance (e.g., within the same cloud subnet or VLAN).
  3. Trigger platform enumeration: Interact with or observe cloud-init's platform detection behavior during instance boot or re-initialization, which causes cloud-init to query a hardcoded local IP address URL.
  4. Intercept or spoof the metadata endpoint: Position on the adjacent network to intercept or respond to cloud-init's request to the hardcoded local IP address, potentially serving malicious configuration data.
  5. Achieve root access: Because cloud-init grants root-level trust to the hardcoded URL on non-x86 platforms, the attacker's response is processed with root privileges, enabling arbitrary command execution or configuration injection on the target system (cloud-init Release 25.1.3, Red Hat Bugzilla).

Indicators of compromise

  • Network: Unexpected HTTP/HTTPS requests from a cloud instance to a hardcoded local IP address (link-local or loopback range) during or after boot, particularly on non-x86 systems; unusual outbound connections from the cloud-init process to metadata-like endpoints not matching the cloud provider's documented metadata service IP.
  • Logs: Cloud-init logs (/var/log/cloud-init.log, /var/log/cloud-init-output.log) showing platform enumeration activity on non-x86 hosts; entries indicating access to unexpected local IP addresses during initialization.
  • File System: Unexpected changes to system configuration files (e.g., /etc/passwd, /etc/sudoers, SSH authorized keys) shortly after instance boot that were not part of the intended cloud-init user-data configuration.
  • Process: Unusual processes spawned by cloud-init with root privileges on non-x86 instances; unexpected cron jobs or systemd units created during the cloud-init initialization phase.

Mitigation and workarounds

The primary remediation is to upgrade cloud-init to version 25.1.3 or later, which removes the unsafe platform identification behavior for non-x86 OpenStack instances (cloud-init Release 25.1.3). As a workaround, ensure that cloud-init's default configuration has platform enumeration disabled (which is the default behavior). Red Hat has issued patches for RHEL 8, 9, and 10 via errata RHSA-2025:10844, RHSA-2025:10848, RHSA-2025:10876, RHSA-2025:10879, RHSA-2025:11295, RHSA-2025:11324, RHSA-2025:11337, and RHSA-2025:11339 (Red Hat Bugzilla). Ubuntu, Fedora, AlmaLinux, Amazon Linux 2, SUSE, and Debian have also released updated packages. Additionally, implementing network segmentation to restrict adjacent network access to cloud instances reduces the exploitability of this vulnerability.

Community reactions

Canonical published a security notification on the Ubuntu Discourse forum specifically addressing the behavior change for non-x86 architectures (Ubuntu Discourse). Ubuntu issued security notice USN-7677-1 for the vulnerability. The CISA vulnerability bulletin for the week of June 23, 2025 included CVE-2024-6174. Community discussion has been limited, with the vulnerability noted primarily in Linux distribution security channels and scanner plugin updates rather than broad social media coverage.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management