CVE-2024-6714

An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:canonical:ubuntu_desktop_provision:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

26 Aug 2025, 19:11

Type Values Removed Values Added
First Time Linux linux Kernel
Canonical
Canonical ubuntu Desktop Provision
Linux
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:canonical:ubuntu_desktop_provision:*:*:*:*:*:*:*:*
References () https://bugs.launchpad.net/ubuntu/+source/provd/+bug/2071574 - () https://bugs.launchpad.net/ubuntu/+source/provd/+bug/2071574 - Exploit, Issue Tracking
References () https://github.com/canonical/ubuntu-desktop-provision/commit/8d9086de0f82894ff27a9e429ff4f45231020092 - () https://github.com/canonical/ubuntu-desktop-provision/commit/8d9086de0f82894ff27a9e429ff4f45231020092 - Patch
References () https://www.cve.org/CVERecord?id=CVE-2024-6714 - () https://www.cve.org/CVERecord?id=CVE-2024-6714 - Third Party Advisory

Information

Published : 2024-07-23 16:15

Updated : 2025-08-26 19:11


NVD link : CVE-2024-6714

Mitre link : CVE-2024-6714

CVE.ORG link : CVE-2024-6714


JSON object : View

Products Affected

canonical

  • ubuntu_desktop_provision

linux

  • linux_kernel
CWE
CWE-73

External Control of File Name or Path

NVD-CWE-noinfo