Skip to content
AWSAWS-2026-015

Out-of-bounds Write in Firecracker virtio-pci Transport

UnratedCVE-2026-5747 · Published Apr 7, 2026 · updated Sep 25, 2026

Bulletin ID:  2026-015-AWS Scope: AWS Content Type:  Important Publication Date: 04/7/2026 3:30 PM PST Description: Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services. We identified CVE-2026-5747 , an out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 that might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. No AWS service is affected. Impacted versions : Firecracker >= 1.13.0 AND Resolution: This issue has been addressed in Firecracker version 1.14.4 and 1.15.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds The virtio PCI transport is opt-in via the --enable-pci command-line fla...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID:  2026-015-AWS Scope: AWS Content Type:  Important Publication Date: 04/7/2026 3:30 PM PST Description: Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services. We identified CVE-2026-5747 , an out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 that might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. No AWS service is affected. Impacted versions : Firecracker >= 1.13.0 AND Resolution: This issue has been addressed in Firecracker version 1.14.4 and 1.15.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds The virtio PCI transport is opt-in via the --enable-pci command-line flag when starting Firecracker. The legacy MMIO transport is the default and is not affected by this issue. Users who have enabled PCI transport can revert to MMIO by removing the --enable-pci flag from their Firecracker invocation. Note that switching from PCI to MMIO transport may result in reduced I/O throughput and increased latency. References CVE-2026-5747 GHSA-776c-mpj7-jm3r Acknowledgement We thank Anthropic for reporting this concern to the AWS Vulnerability Disclosure Program.   Please email aws-security@amazon.com with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-015-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-5747 - Out-of-bounds Write in Firecracker virtio-pci Transport Bulletin ID:  2026-015-AWS Scope: AWS Content Type:  Important Publication Date: 04/7/2026 3:30 PM PST Description: Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services. We identified CVE-2026-5747 , an out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 that might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. No AWS service is affected. Impacted versions : Firecracker >= 1.13.0 AND Resolution: This issue has been addressed in Firecracker version 1.14.4 and 1.15.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds The virtio PCI transport is opt-in via the --enable-pci command-line flag when starting Firecracker. The legacy MMIO tran

Severity from
no source yet

More AWS advisories

All AWS
Advisory
Mount Option Injection in Amazon EFS CSI Driver
UnratedApr 17
Issues with AWS Research and Engineering Studio (RES)
UnratedApr 6
Issues with Amazon Athena ODBC Driver
UnratedApr 3
Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme
UnratedApr 2
AWS C Event Stream Streaming Decoder Stack Buffer Overflow
UnratedMar 31
Defense in depth enhancement for CloudFront signing utility in AWS Tools for PowerShell
High7.7Mar 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.