Bug 2456323 (CVE-2026-5747)

Summary: CVE-2026-5747 firecracker: Firecracker: Arbitrary code execution or denial of service via out-of-bounds write in virtio PCI transport
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Firecracker, specifically an out-of-bounds write issue within the virtio PCI transport. A local guest user with root privileges can exploit this by modifying virtio queue configuration registers after device activation. This could lead to crashing the Firecracker Virtual Machine Monitor (VMM) process, resulting in a denial of service. Under specific preconditions, such as using a custom guest kernel or certain snapshot configurations, this flaw may also allow for arbitrary code execution on the host system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2456351, 2456350    
Bug Blocks:    

Description OSIDB Bzimport 2026-04-08 00:01:26 UTC
An out-of-bounds write issue in the virtio PCI transport in Amazon Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations.

To remediate this, users should upgrade to Firecracker 1.14.4 or 1.15.1 and later.