GPU VulnDB

Database/Container, Kubernetes & orchestration

Contrast: malicious host supplies a null-cipher LUKS2 volume, so guest secrets are written in plaintext

CVSS 6.9CVE-2025-71422Container, Kubernetes & orchestrationcurated

Impact

Contrast's Initializer treats a device as protected if cryptsetup open succeeds with the secret seed. LUKS2 metadata is not authenticated, and cryptsetup before 2.8.1 accepts a header naming the null keyslot cipher, so a malicious host can hand a pod VM a crafted volume and the guest will write confidential data in plaintext or under a volume key the host knows. That defeats the exact property a confidential-containers deployment is bought for: on a GPU cloud running tenant workloads in CVM-backed pods, the infrastructure operator can read data the tenant was told the host could not see. Contrast persistent volumes were not integrity protected, so only confidentiality is considered impacted.

Who can reach it

The host or anyone who controls what block device is presented to the pod VM - the infrastructure side of the trust boundary, or an attacker who has already compromised a node. No tenant credentials involved; the whole point is that the host is meant to be untrusted here.

What to do

Upgrade to Contrast 1.12.1, which ships cryptsetup 2.8.1 and disables null ciphers in keyslots when the passphrase is non-empty; 1.13.0 adds detached-header validation in guest memory and integrity protection for secure persistent storage. Prefer 1.13.0 if you rely on secure persistent volumes. Rolling the runtime means restarting the affected pod VMs; data written while running an affected version should be assumed to have been exposed to the host.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.