CVE-2026-5747 Details
Description
An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. To remediate this, users should upgrade to Firecracker 1.14.4 or 1.15.1 and later.
A vulnerability has been identified in Amazon Firecracker versions 1.13.0 through 1.14.3 and 1.15.0, on both x86_64 and aarch64 architectures. The issue arises from an out-of-bounds write in the virtio PCI transport, which could allow a local guest user with root privileges to crash the Firecracker Virtual Machine Monitor (VMM) process or potentially execute arbitrary code on the host. This exploitation is achieved by modifying virtio queue configuration registers after the device has been activated. However, executing code on the host requires additional conditions, such as using a custom guest kernel or specific snapshot configurations.
Users should upgrade to Firecracker versions 1.14.4 or 1.15.1 and later. If PCI transport is enabled, it can be disabled by removing the '--enable-pci' flag from the Firecracker command-line invocation. Note that switching from PCI to MMIO transport may reduce I/O throughput and increase latency.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-015-aws/ | AMZN | Vendor Advisory |
| https://github.com/firecracker-microvm/firecracker/releases/tag/v1.14.4 | AMZN | Release Notes |
| https://github.com/firecracker-microvm/firecracker/releases/tag/v1.15.1 | AMZN | Release Notes |
| https://github.com/firecracker-microvm/firecracker/security/advisories/GHSA-776c-mpj7-jm3r | AMZN | Vendor Advisory |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| amazon firecracker | >= 1.13.0, <= 1.14.3 1.15.0 - 1.15.0 dev |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| Apr 20, 2026 | CVE Modified | AMZN |
| Apr 8, 2026 | New CVE Received | AMZN |