Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAmazon Firecracker
APPAmazon0.18.00.19.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References
Related vulnerabilities
CVE-2026-5747HIGH8.7same product
An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x8...
CVE-2020-27174HIGH7.5same product
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memo...
CVE-2026-1386MEDIUM6.0same product
Podatność UNIX związana ze śledzeniem linków symbolicznych w komponcie jailer w Firecracker w wersji v1.13.1 i...
CVE-2020-16843MEDIUM5.9same product
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress...
CVE-2026-77234CRITICAL9.3same vendor
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled por...