CVE Vulnerabilities

CVE-2020-16843

Published: Aug 04, 2020 | Modified: Aug 19, 2020
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network interface, and an availability problem for the microVM network interface on which the issue is triggered.

Affected Software

Name Vendor Start Version End Version
Firecracker Amazon 0.20.0 (including) 0.20.0 (including)
Firecracker Amazon 0.21.0 (including) 0.21.0 (including)
Firecracker Amazon 0.21.1 (including) 0.21.1 (including)

References