Skip to main content

Vendor/product archive

amazon / firecracker CVEs

Beta · best-effort

5 CVEs tagged to amazon / firecracker1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-5747

Published Apr 8, 2026

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges…

CVSS 8.7 · High
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2026-1386

Published Jan 23, 2026

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the p…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2020-27174

Published Oct 16, 2020

In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16843

Published Aug 4, 2020

In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18960

Published Dec 11, 2019

Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1