CVE-2020-16843: Medium severity amazon firecracker vulnerability
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network interface, and an availability problem for the microVM network interface on which the issue is triggered.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-16843.
What is the severity of CVE-2020-16843?
The severity of CVE-2020-16843 is medium with a severity value of 5.9.
What is affected by CVE-2020-16843?
Firecracker versions 0.20.0, 0.21.0, and 0.21.1 are affected by CVE-2020-16843.
What is the impact of CVE-2020-16843?
The network stack can freeze under heavy ingress traffic, resulting in a denial of service on the microVM when configured with a single network interface.
Is there a fix for CVE-2020-16843?
Yes, the fix for CVE-2020-16843 is available in Firecracker versions 0.20.1 and 0.21.2.