bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: Firecracker

show all
Thursday, August 20, 2026

Firecracker Jailer Symlink Vulnerability Requires Immediate Patching

Firecracker versions 1.13.1 and earlier, plus 1.14.0, have a nasty symlink bug (CVE-2026-1386) that could let attackers overwrite arbitrary host files through the jailer isolation layer. If you're running Firecracker directly, you need to update now—AWS services using Firecracker aren't affected due to their access restrictions, but self-hosted deployments should patch immediately.

source: [aws/security-bulletin]

Firecracker Virtio-PCI Vulnerability Requires Immediate Patching

Firecracker versions 1.13.0–1.14.3 and 1.15.0 have a critical out-of-bounds write bug (CVE-2026-5747) in virtio-pci transport affecting x86_64 and aarch64. A local guest root user could crash the VMM or potentially execute code on the host. Update to patched versions immediately—no AWS services are impacted, but your self-hosted Firecracker deployments need attention.

source: [aws/security-bulletin]