CVE-2020-27174: High severity amazon firecracker vulnerability
Published Oct 16, 2020
·Updated
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.
Affected Software
2 affected components
Amazon Firecracker<0.21.3
Amazon Firecracker>=0.22.0<0.22.1
Remediation
Patch Available
Patch Available
Event History
Oct 16, 2020
CVE Published
via MITRE·04:06 AM
Data Sourced
via MITRE·04:06 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-27174.
2
What is the severity of CVE-2020-27174?
The severity of CVE-2020-27174 is high, with a CVSS score of 7.5.
3
Which software versions are affected by CVE-2020-27174?
Versions before 0.21.3 and 0.22.x before 0.22.1 of Amazon AWS Firecracker are affected by CVE-2020-27174.
4
What is the impact of CVE-2020-27174?
CVE-2020-27174 can result in a memory leak on the microVM emulation thread, potentially occupying more memory than intended on the host.
5
How can I fix CVE-2020-27174?
Update Amazon AWS Firecracker to version 0.21.3 or 0.22.1 to mitigate CVE-2020-27174.