Database/Container, Kubernetes & orchestration
Contrast: flawed CopyFile policy check lets the untrusted host write arbitrary files into the confidential guest
Impact
Contrast is used to run Kubernetes workloads inside confidential VMs so that the host - the cloud or colocation operator, or anyone who has compromised it - cannot tamper with the workload. The Kata agent policies the Contrast CLI generates verify CopyFile requests incorrectly, so a process on the untrusted host that can reach the agent's VSOCK endpoint can chain CopyFile requests to overwrite security-critical files inside the guest root filesystem, or manoeuvre the workload into disclosing its own data. That is full takeover of the guest and it removes the one property the deployment was bought for: the attestation-backed claim that a host-side attacker cannot reach tenant data or model weights. For a GPU fleet running confidential inference, every guest on a compromised or malicious node must be treated as compromised, and the attestation evidence those guests produced cannot be trusted retroactively.
Who can reach it
A process on the untrusted host able to connect to the Kata agent VSOCK - no guest credentials and no authentication to the workload required. Not reachable from inside the guest or from the network; it needs host-side code execution or a hostile host.
What to do
Upgrade Contrast to 1.19.1 or later and regenerate the Kata agent policies with the new CLI, then redeploy the affected workloads so they start under the corrected policy - existing pods keep the old policy until they are recreated. If you cannot upgrade, the advisory says an equivalent rego policy fix can be passed to contrast generate --policy. Either way the confidential pods restart, so plan it as a workload rollout; no host reboot or firmware work is involved.
References
Related entries
- Harbor (harbor-helm, default core.secretName JWT signing key): SUPPLY CHAIN, UNAUTHENTICATED REGISTRY ACCESS: HarborNCVD-2023-011-harbor-harbor-helm-default-core · Harbor (harbor-helm, default core.secretName JWT signing key)High
- Helm: The `lookup` template function discloses in-cluster resources, including Secrets, to a chart authorCVE-2020-11013 · HelmHigh
- runc: Container filesystem breakout via directory traversal in mount handlingCVE-2021-30465 · runcHigh
- Argo CD: Authorization bypass lets an Application be synced to a destination it is not permitted to reachCVE-2023-22736 · Argo CDHigh
- KubeVirt CDI: PVCs can be cloned from unauthorized namespaces via DataImportCronCVE-2025-14459 · KubeVirt CDIHigh
- Helm: Crafted Chart.yaml plus a symlinked Chart.lock gives local code execution when dependencies are updatedCVE-2025-53547 · HelmHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.