HIGH🇬🇧 English

CVE-2020-27174

CVSS 7.5v3.1pub. 2020-10-16upd. 2024-11-21

In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Amazon Firecracker

    APP
    Amazon
    < 0.21.30.22.0 – 0.22.1 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2019-18960CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w implementacji vsock w Amazon Firecracker

CVE-2026-5747HIGH8.7ten sam produkt

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x8...

CVE-2026-1386MEDIUM6.0ten sam produkt

Podatność UNIX związana ze śledzeniem linków symbolicznych w komponcie jailer w Firecracker w wersji v1.13.1 i...

CVE-2020-16843MEDIUM5.9ten sam produkt

In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress...

CVE-2026-77234CRITICAL9.3ten sam vendor

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled por...