Database/Container, Kubernetes & orchestration

Firecracker: Out-of-bounds write in the virtio PCI transport
CVSS 8.7CVE-2026-5747Container, Kubernetes & orchestrationcurated
Impact
Out-of-bounds write in the virtio PCI transport; guest root can crash or potentially compromise the VMM process
Who can reach it
Any tenant guest VM with root inside it
What to do
Upgrade Firecracker; restart microVMs, which for a neocloud means terminating tenant instances
References
Related entries
- Firecracker: Unbounded serial console buffer growth leaks host memoryCVE-2020-27174 · FirecrackerHigh
- Firecracker: Symlink following in the jailer lets a local host user with write access to pre-created jailerCVE-2026-1386 · FirecrackerMedium
- Firecracker: Network stack freezes under heavy ingressCVE-2020-16843 · FirecrackerMedium
- Firecracker: vsock buffer overflow producing potentially exploitable crashesCVE-2019-18960 · FirecrackerCritical
- Red Hat ACM lighthouse: unvalidated EndpointSlice IPs let a spoke cluster hijack cross-cluster service trafficCVE-2026-66787 · Red Hat Advanced Cluster Management lighthouse (cross-cluster service DNS)High
- NGINX Ingress Controller: unsanitized Ingress annotations inject arbitrary NGINX directivesCVE-2026-77180 · NGINX Ingress Controller (Ingress annotation to nginx.conf generator)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.