ELSA-2025-11324

ELSA-2025-11324 - cloud-init security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2025-07-21

Description


[23.4-7.0.2.el8_10.10]
- Fixes regression in cloud-init with module cc_write_files_deferred [Orabug: 37382965]
- Update IPv6 IMDS endpoint to ULA and drop NIC identifier [Orabug: 35965980]
- Enable IPv6 [Orabug: 36502414]
- Added missing services in rhel/systemd/cloud-init.service [Orabug: 32183938]
- Increase retry value and add timeout for OCI [Orabug: 35329883]
- Fix log file permissions [Orabug: 35302985]
- Update detection logic for OL distros in config template [Orabug: 34845400]
- Added missing services in cloud-init.service.tmpl for sshd [Orabug: 32183938]
- Forward port applicable cloud-init 18.4-2.0.3 changes to cloud-init-18-5 [Orabug: 30435672]
- limit permissions [Orabug: 31352433]
- Changes to ignore all enslaved interfaces [Orabug: 30092148]
- Fix swap file size allocation logic to allocate maxsize [Orabug: 29952349]
- Make Oracle datasource detect dracut based config files [Orabug: 29956753]
- add modified version of enable-ec2_utils-to-stop-retrying-to-get-ec2-metadata.patch:
1. Enable ec2_utils.py having a way to stop retrying to get ec2 metadata
2. Apply stop retrying to get ec2 metadata to helper/openstack.py MetadataReader
Resolves: Oracle-Bug:41660 (Bugzilla)
- added OL to list of known distros

[23.4.0.1]
- Apply OpenELA fixes

[23.4-7.el8.10]
- ci-fix-Don-t-attempt-to-identify-non-x86-OpenStack-inst.patch [RHEL-100606]
- ci-fix-strict-disable-in-ds-identify-on-no-datasources-.patch [RHEL-100606]
- Resolves: RHEL-100606
(CVE-2024-6174 cloud-init: From CVEorg collector [rhel-8.10.z])


Related CVEs


CVE-2024-6174

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) cloud-init-23.4-7.0.2.el8_10.10.src.rpm6ff02b7febdc7e4b71914a1b07911e2b322e3f4b7ff535da9af11fd960ee4278-ol8_aarch64_appstream
cloud-init-23.4-7.0.2.el8_10.10.noarch.rpm2225b5b4c7a6f1c32e9ede1eb284af6a247eb71aad933f3eda17b432d21219f1-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) cloud-init-23.4-7.0.2.el8_10.10.src.rpm6ff02b7febdc7e4b71914a1b07911e2b322e3f4b7ff535da9af11fd960ee4278-ol8_x86_64_appstream
cloud-init-23.4-7.0.2.el8_10.10.noarch.rpm2225b5b4c7a6f1c32e9ede1eb284af6a247eb71aad933f3eda17b432d21219f1-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete