GPU VulnDB

Database/Container, Kubernetes & orchestration

Contrast: generated Kata policies accept image_guest_pull storage without digest check, allowing image substitution

CVSS 7.6CVE-2026-100833Container, Kubernetes & orchestrationcurated

Impact

Contrast generates Kata Containers runtime policies that are supposed to pin exactly which container images a confidential pod may run. A bad rebase during a Kata update introduced an allow_storage rule that accepts storage entries using the image_guest_pull driver without verifying the image digest, so the policy no longer detects every image substitution. Anyone who can talk to the Kata agent API - explicitly including a Kubernetes cluster administrator, who is inside Contrast's threat model as an untrusted party - can swap in a different image carrying an exploit payload as long as it satisfies the remaining policy rules. For an operator running confidential AI workloads on behalf of tenants, this removes the integrity guarantee the deployment was chosen for: the attested workload and the running workload can differ. Affects 1.14.0 up to but not including 1.23.1.

Who can reach it

Access to the Kata agent API of a confidential pod - in Contrast's model, the Kubernetes cluster administrator or anyone who has compromised the untrusted control plane. Authenticated cluster-level access, not remote-anonymous.

What to do

Upgrade Contrast to 1.23.1 or later and regenerate runtime policies for every deployment - policies produced by an affected version stay weak until regenerated, so a version bump alone is not sufficient. Redeploy affected confidential workloads with the new policies; no node reboot or firmware work is involved.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.