[Git][security-tracker-team/security-tracker][master] new cloud-init issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Jun 27 08:30:10 BST 2025



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
256fc4a0 by Moritz Muehlenhoff at 2025-06-27T09:29:47+02:00
new cloud-init issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -140,13 +140,18 @@ CVE-2025-30131 (An issue was discovered on IROAD Dashcam FX2 devices. An unauthe
 CVE-2025-29331 (An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote a ...)
 	TODO: check
 CVE-2024-6174 (When a non-x86 platform is detected, cloud-init grants root access to  ...)
-	TODO: check
+	- cloud-init <unfixed>
+	NOTE: https://github.com/canonical/cloud-init/commit/f43937f0b462734eb9c76700491c18fe4133c8e1
+	NOTE: https://github.com/advisories/GHSA-w8g9-wp36-fchj
 CVE-2024-56915 (Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Si ...)
 	- netbox <itp> (bug #1017079)
 CVE-2024-52928 (Arc before 1.26.1 on Windows has a bypass issue in the site settings t ...)
 	TODO: check
 CVE-2024-11584 (cloud-initthrough 25.1.2 includes the systemd socket unitcloud-init-ho ...)
-	TODO: check
+	- cloud-init <unfixed>
+	NOTE: https://github.com/canonical/cloud-init/commit/8b45006c4765fd75f20ce244571b563dbc49d4f2
+	NOTE: https://github.com/canonical/cloud-init/pull/6265
+	NOTE: https://github.com/advisories/GHSA-3xmh-hrxh-fx8j
 CVE-2025-6669 (A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has be ...)
 	NOT-FOR-US: gooaclok819 sublinkX
 CVE-2025-6668 (A vulnerability was found in code-projects Inventory Management System ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/256fc4a02b2792b9b2e1b1516bae80bad993c145

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/256fc4a02b2792b9b2e1b1516bae80bad993c145
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250627/d758a603/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list