CVE-2012-6639: Canonical Cloud-Init

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.

Affected products

  • Canonical Cloud-Init: before 0.7.0 (fixed in 0.7.0)
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Suse Linux Enterprise Server: version 11 only

Published 2019-11-25. Last modified 2026-06-16.