VDB
CVE-2020-27174
CVE-2020-27174
PUBLISHED
CVSS 7.5 HIGH
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.
EPSS 0.56% · 68.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.56%
68.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| amazon | firecracker | 0.22.0, 0 |
| n/a | n/a | n/a |
Timeline
- Oct 16, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://github.com/firecracker-microvm/firecracker/issues/2177 url
- https://github.com/firecracker-microvm/firecracker/pull/2178 url
- https://github.com/firecracker-microvm/firecracker/pull/2179 url
- [oss-security] 20201023 CVE-2020-27174: Firecracker serial console emulation may allocate an unbounded amount of memory mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2020-27174 advisory