OVERVIEW CVE-2026-5747 is an out-of-bounds write vulnerability in the virtio PCI transport layer affecting Firecracker versions 1.13.0 through 1.14.3 and 1.15.0 on both x86_64 and aarch64 architectures. A local guest user with root privileges can modify virtio queue configuration registers after device activation to trigger the vulnerability, potentially crashing the Firecracker Virtual Machine Monitor (VMM) process or executing arbitrary code on the host system. Code execution requires additional preconditions such as a custom guest kernel or specific snapshot configurations. SEVERITY The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) with a local attack vector, high attack complexity, and high-level privileges required. The impact is severe across confidentiality, integrity, and availability of the host system. The attack requires physical or logical access to the guest environment and cannot be exploited remotely. While the FAUCET Risk Score of 48.0/100 indicates moderate concern, the potential for host-level code execution represents a significant breach of the hypervisor isolation boundary. EXPLOITATION STATUS There is no current evidence of active exploitation in the wild, as indicated by the CVE not appearing on the Known Exploited Vulnerabilities (KEV) catalog and its inactive status on exploit tracking lists. The extremely low EPSS score of 0.00018 suggests minimal real-world exploitation probability relative to other disclosed vulnerabilities. Users should prioritize patching by upgrading to Firecracker 1.14.4, 1.15.1, or later versions as a preventive measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.13.0, <= 1.14.3CPE matchmatch criteria | cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:* | ||
1.15.0CPE matchmatch criteria | cpe:2.3:a:amazon:firecracker:1.15.0:-:*:*:*:*:*:* | ||
1.15.0CPE matchmatch criteria | cpe:2.3:a:amazon:firecracker:1.15.0:dev:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.