Database/Container, Kubernetes & orchestration

Contrast: generated Kata policies accept image_guest_pull storage without digest check, allowing image substitution
Impact
Contrast generates Kata Containers runtime policies that are supposed to pin exactly which container images a confidential pod may run. A bad rebase during a Kata update introduced an allow_storage rule that accepts storage entries using the image_guest_pull driver without verifying the image digest, so the policy no longer detects every image substitution. Anyone who can talk to the Kata agent API - explicitly including a Kubernetes cluster administrator, who is inside Contrast's threat model as an untrusted party - can swap in a different image carrying an exploit payload as long as it satisfies the remaining policy rules. For an operator running confidential AI workloads on behalf of tenants, this removes the integrity guarantee the deployment was chosen for: the attested workload and the running workload can differ. Affects 1.14.0 up to but not including 1.23.1.
Who can reach it
Access to the Kata agent API of a confidential pod - in Contrast's model, the Kubernetes cluster administrator or anyone who has compromised the untrusted control plane. Authenticated cluster-level access, not remote-anonymous.
What to do
Upgrade Contrast to 1.23.1 or later and regenerate runtime policies for every deployment - policies produced by an affected version stay weak until regenerated, so a version bump alone is not sufficient. Redeploy affected confidential workloads with the new policies; no node reboot or firmware work is involved.
References
Related entries
- Kubeflow Pipelines (Data Science Pipelines V1 API Argo Workflow spec path): The V1 API path accepts an arbitrary ArgoCVE-2026-18621 · Kubeflow Pipelines (Data Science Pipelines V1 API Argo Workflow spec path)High
- Traefik Gateway API provider: colliding route identities let one namespace overwrite another's backendCVE-2026-71327 · Traefik Kubernetes Gateway API provider (HTTPRoute/GRPCRoute/TCPRoute/TLSRoute identity construction)High
- Cilium (mutual authentication, TLS certificate chain handling): Mutual authentication, the control an operator turns onNCVD-2026-045-cilium-mutual-authentication-tls · Cilium (mutual authentication, TLS certificate chain handling)High
- Docker / moby: `docker cp` symlink-exchange TOCTOU gives arbitrary host read/write as rootCVE-2018-15664 · Docker / mobyHigh
- Kubernetes (kube-apiserver): "Billion laughs": malicious YAML/JSON payload consumes all apiserver memoryCVE-2019-11253 · Kubernetes (kube-apiserver)High
- Docker / moby: Docker Engine in debug mode writes secrets into the debug logCVE-2019-13509 · Docker / mobyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.