CVE-2024-6174: Canonical Cloud-Init

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.

Affected products

  • Canonical Cloud-Init: before 25.1.3 (fixed in 25.1.3)

Published 2025-06-26. Last modified 2026-06-17.