GPU VulnDB

Database/Container, Kubernetes & orchestration

Contrast: untrusted host can write arbitrary files into a confidential container via an unbacked VOLUME path

CVSS 5.1CVE-2025-71424Container, Kubernetes & orchestrationcurated

Impact

Contrast runs confidential containers on Kubernetes, so its whole value is that the host cannot tamper with what runs inside the guest. A Dockerfile VOLUME directive is only a hint to Kubernetes, but containerd adds a mount point for it when Kubernetes supplies none, which requires the runtime to accept arbitrary data pushed to the Kata agent. On bare-metal Contrast deployments running an image that declares a VOLUME with no matching Kubernetes mount, the untrusted host can write an arbitrary file tree below that path inside the guest, breaking integrity of a directory the application usually depends on. AKS deployments are not affected. For an operator using confidential containers to isolate tenant model workloads from the host, this narrows the guarantee they bought the runtime for; NVD records integrity impact only, no confidentiality or availability effect.

Who can reach it

The untrusted host or anyone with control of it, against a bare-metal Contrast deployment whose workload image declares a VOLUME that no Kubernetes mount covers. Adjacent-network vector with low privileges per the CVSS string.

What to do

Upgrade Contrast to 1.9.1, which rejects this configuration in contrast generate, then regenerate the deployment manifests and roll the affected workloads; the rollout is a redeploy of the confidential pods, not a host reboot. Where you cannot upgrade yet, audit workload images for VOLUME directives and add an explicit Kubernetes mount at every such path, or rebuild the images without them.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.