Firecracker Security Alert: Virtio-PCI Vulnerability Could Lead to Out-of-Bounds Memory Access
ID: 0361ff74-dafa-58c7-8de3-d75cfec73648
STIX ID: report--0361ff74-dafa-58c7-8de3-d75cfec73648
Feed Name: securityonline.info
**Executive summary:** Firecracker (CVE-2026-5747) is a high-severity (CVSS 8.7) out-of-bounds write vulnerability in the virtio-pci transport that allows a root-privileged guest to change queue_size after activation, potentially causing denial-of-service, large out-of-bounds writes (up to 524,284 bytes), and, under specific preconditions, host memory corruption; AWS has released patches (1.14.4 and 1.15.1) and recommends removing the --enable-pci flag as a temporary mitigation (legacy MMIO is not affected).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
