CVE-2025-71422 Details
Description
Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM. LUKS2 volume metadata is not authenticated and, with cryptsetup versions prior to 2.8.1, a header specifying the null keyslot encryption algorithm (cipher_null-ecb) is accepted without error. Because the Contrast Initializer assumes a device is protected if `cryptsetup open` succeeds with the secret seed, the guest will open the attacker-supplied volume and write secret data in plaintext, or under a volume key known to the attacker, allowing the host to read confidential data that should have been encrypted. Contrast v1.12.1 ships cryptsetup 2.8.1, which disables null ciphers in keyslots when the passphrase is non-empty; v1.13.0 adds detached-header validation in guest memory and integrity protection for secure persistent storage. Contrast persistent volumes were not integrity protected, so integrity impact is not considered.
A vulnerability exists in Contrast, a Kubernetes runtime for confidential containers, in versions prior to 1.12.1. The issue arises in the secure persistent volume feature, which can be exploited by a malicious host that supplies a crafted LUKS2 volume to a pod VM. The vulnerability stems from the fact that LUKS2 volume metadata is not authenticated. Additionally, cryptsetup versions prior to 2.8.1 accept headers that specify the null keyslot encryption algorithm without error. The Contrast Initializer assumes a device is protected if the 'cryptsetup open' command succeeds with the secret seed. As a result, the guest VM will open the attacker-supplied volume and write secret data in plaintext or under a volume key known to the attacker. This allows the host to read confidential data that should have been encrypted.
Users can upgrade to Contrast version 1.12.1 or 1.13.0, both of which address this vulnerability by incorporating cryptsetup 2.8.1, which disables null ciphers in keyslots when the passphrase is non-empty. Version 1.13.0 also adds detached-header validation in guest memory and integrity protection for secure persistent storage.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Edgelesssys Contrast | <= v1.12.0 (semver) <= v1.13.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion