HIGH🇵🇱 Wersja polska

CVE-2026-5747

CVSS 8.7v4.0pub. 2026-04-08upd. 2026-07-24

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. To remediate this, users should upgrade to Firecracker 1.14.4 or 1.15.1 and later.

CVSS Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Amazon Firecracker

    APP
    Amazon
    1.15.01.13.0 – 1.14.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2019-18960CRITICAL9.8PL ✓same product

Buffer overflow w implementacji vsock w Amazon Firecracker

CVE-2020-27174HIGH7.5same product

In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memo...

CVE-2026-1386MEDIUM6.0same product

Podatność UNIX związana ze śledzeniem linków symbolicznych w komponcie jailer w Firecracker w wersji v1.13.1 i...

CVE-2020-16843MEDIUM5.9same product

In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress...

CVE-2026-77234CRITICAL9.3same vendor

Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled por...