HIGH🇵🇱 Wersja polska

CVE-2020-27174

CVSS 7.5v3.1pub. 2020-10-16upd. 2024-11-21

In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Amazon Firecracker

    APP
    Amazon
    < 0.21.30.22.0 – 0.22.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-18960CRITICAL9.8PL ✓same product

Buffer overflow w implementacji vsock w Amazon Firecracker

CVE-2026-5747HIGH8.7same product

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x8...

CVE-2026-1386MEDIUM6.0same product

Podatność UNIX związana ze śledzeniem linków symbolicznych w komponcie jailer w Firecracker w wersji v1.13.1 i...

CVE-2020-16843MEDIUM5.9same product

In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress...

CVE-2026-77234CRITICAL9.3same vendor

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled por...