Bug#1108403: cloud-init: CVE-2024-6174
On 2025-06-28 18:15:08 +0200 (+0200), thomas@goirand.fr wrote:
[...]
FYI, I expect most OpenStack operators to configure a config drive
by default, as it is the most reliable metadata source.
Yes, the main reason some of them prefer/recommend the network
metadata source is that it can be updated over time, while the
configdrive content is (currently) frozen at the time its associated
server instance is created so things like default gateways, static
routes and DNS resolver addresses may grow stale as the operator
makes adjustments to their environment.
But since we're talking about a very small subset of clouds right
now (specifically those with non-amd64 compute nodes), I think the
behavior change is probably not a major concern.
--
Jeremy Stanley
Reply to: