GPU VulnDB

Database/Container, Kubernetes & orchestration

Contrast: flawed CopyFile policy check lets the untrusted host write arbitrary files into the confidential guest

CVSS 8.6CVE-2026-100838Container, Kubernetes & orchestrationcurated

Impact

Contrast is used to run Kubernetes workloads inside confidential VMs so that the host - the cloud or colocation operator, or anyone who has compromised it - cannot tamper with the workload. The Kata agent policies the Contrast CLI generates verify CopyFile requests incorrectly, so a process on the untrusted host that can reach the agent's VSOCK endpoint can chain CopyFile requests to overwrite security-critical files inside the guest root filesystem, or manoeuvre the workload into disclosing its own data. That is full takeover of the guest and it removes the one property the deployment was bought for: the attestation-backed claim that a host-side attacker cannot reach tenant data or model weights. For a GPU fleet running confidential inference, every guest on a compromised or malicious node must be treated as compromised, and the attestation evidence those guests produced cannot be trusted retroactively.

Who can reach it

A process on the untrusted host able to connect to the Kata agent VSOCK - no guest credentials and no authentication to the workload required. Not reachable from inside the guest or from the network; it needs host-side code execution or a hostile host.

What to do

Upgrade Contrast to 1.19.1 or later and regenerate the Kata agent policies with the new CLI, then redeploy the affected workloads so they start under the corrected policy - existing pods keep the old policy until they are recreated. If you cannot upgrade, the advisory says an equivalent rego policy fix can be passed to contrast generate --policy. Either way the confidential pods restart, so plan it as a workload rollout; no host reboot or firmware work is involved.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.