PT-2026-31052 · Amazon · Amazon Aws Firecracker

Aegiryy

+3

·

Published

2026-04-07

·

Updated

2026-06-01

·

CVE-2026-5747

CVSS v3.1

7.5

High

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Amazon Firecracker versions 1.13.0 through 1.14.3 and version 1.15.0
Description A flaw exists in the virtio PCI transport of Amazon Firecracker that could allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host. This is possible through modification of virtio queue configuration registers after device activation. Code execution on the host requires additional conditions, such as a custom guest kernel or specific snapshot configurations.
Recommendations Upgrade to Amazon Firecracker version 1.14.4 or later. Upgrade to Amazon Firecracker version 1.15.1 or later.

Fix

Divide By Zero

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-5747
OPENSUSE-SU-2026:10561-1

Affected Products

Amazon Aws Firecracker