CVE-2024-6714

An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:canonical:ubuntu_desktop_provision:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

26 Aug 2025, 19:11

Type Values Removed Values Added
References () https://bugs.launchpad.net/ubuntu/+source/provd/+bug/2071574 - () https://bugs.launchpad.net/ubuntu/+source/provd/+bug/2071574 - Exploit, Issue Tracking
References () https://github.com/canonical/ubuntu-desktop-provision/commit/8d9086de0f82894ff27a9e429ff4f45231020092 - () https://github.com/canonical/ubuntu-desktop-provision/commit/8d9086de0f82894ff27a9e429ff4f45231020092 - Patch
References () https://www.cve.org/CVERecord?id=CVE-2024-6714 - () https://www.cve.org/CVERecord?id=CVE-2024-6714 - Third Party Advisory
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:canonical:ubuntu_desktop_provision:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Canonical ubuntu Desktop Provision
Canonical
Linux
CWE NVD-CWE-noinfo

21 Nov 2024, 09:50

Type Values Removed Values Added
References () https://bugs.launchpad.net/ubuntu/+source/provd/+bug/2071574 - () https://bugs.launchpad.net/ubuntu/+source/provd/+bug/2071574 -
References () https://github.com/canonical/ubuntu-desktop-provision/commit/8d9086de0f82894ff27a9e429ff4f45231020092 - () https://github.com/canonical/ubuntu-desktop-provision/commit/8d9086de0f82894ff27a9e429ff4f45231020092 -
References () https://www.cve.org/CVERecord?id=CVE-2024-6714 - () https://www.cve.org/CVERecord?id=CVE-2024-6714 -

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en provd anterior a la versión 0.1.5 con un binario setuid, que permite a un atacante local escalar sus privilegios.

23 Jul 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-23 16:15

Updated : 2025-08-26 19:11


NVD link : CVE-2024-6714

Mitre link : CVE-2024-6714

CVE.ORG link : CVE-2024-6714


JSON object : View

Products Affected

canonical

  • ubuntu_desktop_provision

linux

  • linux_kernel
CWE
CWE-73

External Control of File Name or Path

NVD-CWE-noinfo