High severity7.5NVD Advisory· Published Oct 16, 2020· Updated Jun 17, 2026
CVE-2020-27174
CVE-2020-27174
Description
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:*range: <0.21.3
- (no CPE)range: <0.21.3, <0.22.1
- (no CPE)
Patches
Vulnerability mechanics
References
4- github.com/firecracker-microvm/firecracker/pull/2178nvdPatchThird Party Advisory
- github.com/firecracker-microvm/firecracker/pull/2179nvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2020/10/23/1nvdThird Party Advisory
- github.com/firecracker-microvm/firecracker/issues/2177nvdThird Party Advisory
News mentions
0No linked articles in our index yet.