CVE-2026-5747

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. To remediate this, users should upgrade to Firecracker 1.14.4 or 1.15.1 and later.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:firecracker:1.15.0:-:*:*:*:*:*:*
cpe:2.3:a:amazon:firecracker:1.15.0:dev:*:*:*:*:*:*

History

24 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Un problema de escritura fuera de límites en el transporte PCI de virtio en Amazon Firecracker 1.13.0 hasta 1.14.3 y 1.15.0 en x86_64 y aarch64 podría permitir a un usuario invitado local con privilegios de root bloquear el proceso VMM de Firecracker o potencialmente ejecutar código arbitrario en el host mediante la modificación de los registros de configuración de la cola virtio después de la activación del dispositivo. Lograr la ejecución de código en el host requiere precondiciones adicionales, como el uso de un kernel invitado personalizado o configuraciones de instantáneas específicas. Para remediar esto, los usuarios deben actualizar a Firecracker 1.14.4 o 1.15.1 y versiones posteriores.

01 Jun 2026, 12:52

Type Values Removed Values Added
References () https://aws.amazon.com/security/security-bulletins/2026-015-aws/ - () https://aws.amazon.com/security/security-bulletins/2026-015-aws/ - Vendor Advisory
References () https://github.com/firecracker-microvm/firecracker/releases/tag/v1.14.4 - () https://github.com/firecracker-microvm/firecracker/releases/tag/v1.14.4 - Release Notes
References () https://github.com/firecracker-microvm/firecracker/releases/tag/v1.15.1 - () https://github.com/firecracker-microvm/firecracker/releases/tag/v1.15.1 - Release Notes
References () https://github.com/firecracker-microvm/firecracker/security/advisories/GHSA-776c-mpj7-jm3r - () https://github.com/firecracker-microvm/firecracker/security/advisories/GHSA-776c-mpj7-jm3r - Vendor Advisory
CPE cpe:2.3:a:amazon:firecracker:1.15.0:dev:*:*:*:*:*:*
cpe:2.3:a:amazon:firecracker:1.15.0:-:*:*:*:*:*:*
cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:*
First Time Amazon
Amazon firecracker

20 Apr 2026, 16:16

Type Values Removed Values Added
Summary (en) An out-of-bounds write issue in the virtio PCI transport in Amazon Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. To remediate this, users should upgrade to Firecracker 1.14.4 or 1.15.1 and later. (en) An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. To remediate this, users should upgrade to Firecracker 1.14.4 or 1.15.1 and later.

08 Apr 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 00:16

Updated : 2026-07-24 09:10


NVD link : CVE-2026-5747

Mitre link : CVE-2026-5747

CVE.ORG link : CVE-2026-5747


JSON object : View

Products Affected

amazon

  • firecracker
CWE
CWE-369

Divide By Zero

CWE-787

Out-of-bounds Write