PT-2020-16647 · Amazon+1 · Amazon Aws Firecracker+1
Alexandra Iordache
·
Published
2020-10-16
·
Updated
2021-07-21
·
CVE-2020-27174
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Amazon AWS Firecracker versions 0.21.3 and earlier, 0.22.x before 0.22.1
Description
The issue is related to the serial console buffer, which can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.
Recommendations
For Amazon AWS Firecracker versions 0.21.3 and earlier, update to version 0.21.3 or later.
For Amazon AWS Firecracker versions 0.22.x before 0.22.1, update to version 0.22.1 or later.
Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Amazon Aws Firecracker