PT-2026-31052 · Amazon · Amazon Aws Firecracker

·

CVE-2026-5747

·

Published

2026-04-07

·

Updated

2026-06-11

CVSS v4.0

8.7

High

VectorAV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Firecracker versions 1.13.0 through 1.14.3 Firecracker version 1.15.0
Description An out-of-bounds write issue exists in the virtio PCI transport on x86 64 and aarch64 architectures. A local guest user with root privileges can exploit this by modifying virtio queue configuration registers after device activation to crash the Firecracker VMM process or potentially execute arbitrary code on the host. Host code execution requires additional preconditions, such as specific snapshot configurations or the use of a custom guest kernel.
Recommendations For versions 1.13.0 through 1.14.3, upgrade to version 1.14.4 or later. For version 1.15.0, upgrade to version 1.15.1 or later.

Exploit

Fix

Memory Corruption

Divide By Zero

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5747
GHSA-776C-MPJ7-JM3R
OPENSUSE-SU-2026:10561-1

Affected Products

Amazon Aws Firecracker