bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: virtio-pci

show all
Thursday, August 20, 2026

Firecracker Virtio-PCI Vulnerability Requires Immediate Patching

Firecracker versions 1.13.0–1.14.3 and 1.15.0 have a critical out-of-bounds write bug (CVE-2026-5747) in virtio-pci transport affecting x86_64 and aarch64. A local guest root user could crash the VMM or potentially execute code on the host. Update to patched versions immediately—no AWS services are impacted, but your self-hosted Firecracker deployments need attention.

source: [aws/security-bulletin]