
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-6174 is a permissions and authentication flaw in Canonical's cloud-init tool where, upon detecting a non-x86 platform, cloud-init incorrectly grants root access to a hardcoded URL with a local IP address. This behavior is classified under CWE-276 (Incorrect Default Permissions) and CWE-287 (Improper Authentication). All versions of cloud-init prior to 25.1.3 are affected (versions 0.7.9 through <25.1.3). The vulnerability was publicly disclosed on June 26, 2025, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is that cloud-init, when it identifies a non-x86 platform (e.g., ARM, s390x, or other architectures), attempts to enumerate the platform type and in doing so grants root-level access to a hardcoded local IP address URL — likely a metadata service endpoint — without proper authentication controls (CWE-276, CWE-287). To mitigate this by default, cloud-init's default configuration disables platform enumeration, meaning systems using non-default configurations or explicitly enabling platform enumeration on non-x86 hardware are at risk. The attack vector is adjacent network (AV:A), requiring no privileges or user interaction, making it exploitable by any attacker on the same network segment. The fix in version 25.1.3 prevents cloud-init from attempting to identify non-x86 OpenStack instances, eliminating the unsafe access grant (cloud-init Release 25.1.3, Red Hat Bugzilla).
Successful exploitation allows an adjacent network attacker to gain root-level access to the affected cloud instance without any credentials or user interaction, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive data, modify system configurations, install malware, or disrupt services on the compromised host. The vulnerability is particularly relevant in cloud and virtualized environments running non-x86 architectures (e.g., ARM-based or IBM Z cloud instances) where cloud-init is widely deployed for instance initialization (Red Hat Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit code known at this time, and no evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.016% (0.000160), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. The vulnerability is detectable by multiple commercial scanners including Qualys and Nessus (Red Hat Advisory).
/var/log/cloud-init.log, /var/log/cloud-init-output.log) showing platform enumeration activity on non-x86 hosts; entries indicating access to unexpected local IP addresses during initialization./etc/passwd, /etc/sudoers, SSH authorized keys) shortly after instance boot that were not part of the intended cloud-init user-data configuration.The primary remediation is to upgrade cloud-init to version 25.1.3 or later, which removes the unsafe platform identification behavior for non-x86 OpenStack instances (cloud-init Release 25.1.3). As a workaround, ensure that cloud-init's default configuration has platform enumeration disabled (which is the default behavior). Red Hat has issued patches for RHEL 8, 9, and 10 via errata RHSA-2025:10844, RHSA-2025:10848, RHSA-2025:10876, RHSA-2025:10879, RHSA-2025:11295, RHSA-2025:11324, RHSA-2025:11337, and RHSA-2025:11339 (Red Hat Bugzilla). Ubuntu, Fedora, AlmaLinux, Amazon Linux 2, SUSE, and Debian have also released updated packages. Additionally, implementing network segmentation to restrict adjacent network access to cloud instances reduces the exploitability of this vulnerability.
Canonical published a security notification on the Ubuntu Discourse forum specifically addressing the behavior change for non-x86 architectures (Ubuntu Discourse). Ubuntu issued security notice USN-7677-1 for the vulnerability. The CISA vulnerability bulletin for the week of June 23, 2025 included CVE-2024-6174. Community discussion has been limited, with the vulnerability noted primarily in Linux distribution security channels and scanner plugin updates rather than broad social media coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."