CVE-2020-27174

In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:*

Information

Published : 2020-10-16 05:15

Updated : 2021-07-21 11:39


NVD link : CVE-2020-27174

Mitre link : CVE-2020-27174


JSON object : View

Products Affected

amazon

  • firecracker
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer