
Firecracker-specific surface: CVE-2026-1386: Jailer symlink → arbitrary host file overwrite CVE-2019-18960: virtio-vsock → r/w in VMM process io_uring: still in seccomp allowlist, bypasses filtering The Jailer IS the last defense. If it falls, nothing's left.
Post summary
The snippet enumerates three CVEs affecting Firecracker, detailing a Jailer symlink-based overwrite, virtio-vsock read/write, and a seccomp allowlist bypass via io_uring.
