SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-27174

This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.

HIGH 7.5EPSS 1.74%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.74% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-401
Affected
amazon/firecracker
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.