An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execute arbitrary code on the host via modification of virtio queue configuration registers after device activation. Achieving code execution on the host requires additional preconditions, such as the use of a custom guest kernel or specific snapshot configurations. To remediate this, users should upgrade to Firecracker 1.14.4 or 1.15.1 and later.
Conclusion & alert: CVE-2026-5747 is rated Low Risk (35.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.01%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-08 | — | 0.01% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | ff89ba41-3aa1-4d27-914a-91399e9639e5 |
| 7.5 | 3.1 | HIGH |
|
0.8 | 6.0 | ff89ba41-3aa1-4d27-914a-91399e9639e5 |
| vendor | priority | summary | link |
|---|---|---|---|
suse
|
high | — | https://www.suse.com/security/cve/CVE-2026-5747/ |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| amazon | firecracker | >= 1.13.0, <= 1.14.3 | cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:* |
| amazon | firecracker | 1.15.0 | cpe:2.3:a:amazon:firecracker:1.15.0:-:*:*:*:*:*:* |
| amazon | firecracker | 1.15.0 | cpe:2.3:a:amazon:firecracker:1.15.0:dev:*:*:*:*:*:* |