Database/Container, Kubernetes & orchestration
Contrast: malicious host supplies a null-cipher LUKS2 volume, so guest secrets are written in plaintext
Impact
Contrast's Initializer treats a device as protected if cryptsetup open succeeds with the secret seed. LUKS2 metadata is not authenticated, and cryptsetup before 2.8.1 accepts a header naming the null keyslot cipher, so a malicious host can hand a pod VM a crafted volume and the guest will write confidential data in plaintext or under a volume key the host knows. That defeats the exact property a confidential-containers deployment is bought for: on a GPU cloud running tenant workloads in CVM-backed pods, the infrastructure operator can read data the tenant was told the host could not see. Contrast persistent volumes were not integrity protected, so only confidentiality is considered impacted.
Who can reach it
The host or anyone who controls what block device is presented to the pod VM - the infrastructure side of the trust boundary, or an attacker who has already compromised a node. No tenant credentials involved; the whole point is that the host is meant to be untrusted here.
What to do
Upgrade to Contrast 1.12.1, which ships cryptsetup 2.8.1 and disables null ciphers in keyslots when the passphrase is non-empty; 1.13.0 adds detached-header validation in guest memory and integrity protection for secure persistent storage. Prefer 1.13.0 if you rely on secure persistent volumes. Rolling the runtime means restarting the affected pod VMs; data written while running an affected version should be assumed to have been exposed to the host.
References
Related entries
- BuildKit: Crafted upload request lets files escape the BuildKit state directory onto the hostCVE-2026-15789 · BuildKitMedium
- Istio: Envoy RBAC header matching flaw bypasses header-based authorization policyCVE-2026-31838 · IstioMedium
- containerd: crafted OCI image index exhausts node CPU and memory during image pullCVE-2026-53493 · containerd (OCI index graph handling in PullImage)Medium
- Kyverno: unvalidated ServiceCall URL turns the cluster-wide ServiceAccount into a confused deputyCVE-2026-84199 · Kyverno admission controller (APICall ServiceCall URL field)Medium
- NGINX: HTTP/3 handshake can overflow a heap buffer in the worker, restarting it or corrupting dataCVE-2026-90439 · NGINX ngx_http_v3_module (HTTP/3 TLS handshake with OpenSSL <= 3.5.0)Medium
- Istio: DENY AuthorizationPolicy with wildcard-suffix principals silently fails to denyCVE-2020-16844 · IstioMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.