CVE Vulnerabilities

CVE-2020-16843

Published: Aug 04, 2020 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network interface, and an availability problem for the microVM network interface on which the issue is triggered.

Affected Software

Name Vendor Start Version End Version
Firecracker Amazon 0.20.0 (including) 0.20.0 (including)
Firecracker Amazon 0.21.0 (including) 0.21.0 (including)
Firecracker Amazon 0.21.1 (including) 0.21.1 (including)

References