Описание
Recommended update for cloud-init
This update for cloud-init fixes the following issues:
Changes in cloud-init:
-
Fix dependency replace -serial with -pyserial
-
Drop unneeded test dependency on httpretty, fixed long ago
-
Update to version 25.1.3 (bsc#1245401 , CVE-2024-6174, bsc#1245403, CVE-2024-11584)
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1245401
- SUSE Bug 1245403
- SUSE CVE CVE-2024-11584 page
- SUSE CVE CVE-2024-6174 page
Описание
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This is used for the "/run/cloud-init/hook-hotplug-cmd" FIFO. An unprivileged user could trigger hotplug-hook commands.
Затронутые продукты
Ссылки
- CVE-2024-11584
- SUSE Bug 1245403
Описание
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
Затронутые продукты
Ссылки
- CVE-2024-6174
- SUSE Bug 1245401