CVE-2026-1386 PUBLISHED

Arbitrary Host File Overwrite via Symlink in Firecracker Jailer

Assigner: AMZN
Reserved: 23.01.2026 Published: 23.01.2026 Updated: 23.01.2026

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges.

To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H
CVSS Score: 6

Product Status

Vendor AWS
Product Firecracker
Versions Default: unaffected
  • Version 1.13.2 is unaffected
  • Version 1.14.1 is unaffected

References

Problem Types

  • CWE-61: UNIX Symbolic Link (Symlink) Following CWE

Impacts

  • CAPEC-132: Symlink Attack