CVE-2026-100839 Details
Description
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware (OVMF) and on to the Linux kernel, whose AML interpreter executes them. An attacker controlling the host — an assumed adversary in Contrast's threat model — can craft a table with malicious, Turing-complete AML bytecode that the guest kernel interprets with access to the full guest memory, including private pages, resulting in arbitrary code execution and disclosure or modification of confidential guest data. The issue affects the AMD SEV-SNP platforms Metal-QEMU-SNP and Metal-QEMU-SNP-GPU; Metal-QEMU-TDX is not affected because ACPI table contents are measured into RTMR 0 by OVMF on Intel TDX. Version v1.18.0 mitigates the attack by sandboxing the kernel AML interpreter so that it cannot read or write private memory pages. This weakness is not specific to Contrast but is generic to Confidential Computing setups that expose the ACPI interface to the host.
A vulnerability exists in Contrast, a confidential-computing runtime for Kubernetes, in versions prior to 1.18.0. The issue arises from the guest kernel's handling of ACPI/AML, which is susceptible to an AML injection attack known as 'BadAML'. In this vulnerability, ACPI tables containing AML bytecode are transmitted from the untrusted host (QEMU) to the guest firmware (OVMF) and subsequently to the Linux kernel. The kernel's AML interpreter executes this bytecode, which is Turing-complete and has access to the entire guest memory, including private pages. This exploitation leads to arbitrary code execution and the unauthorized disclosure or modification of confidential guest data. The vulnerability is present on AMD SEV-SNP platforms, specifically Metal-QEMU-SNP and Metal-QEMU-SNP-GPU. However, Metal-QEMU-TDX is not affected, as OVMF measures ACPI table contents into RTMR 0 on Intel TDX, preventing such attacks. The vulnerability allows an attacker controlling the host to craft a table with malicious AML bytecode that the guest kernel executes, exploiting the full access to guest memory for unauthorized actions.
Users should upgrade to Contrast version 1.18.0 or later, which addresses this vulnerability by sandboxing the kernel AML interpreter to prevent access to private memory pages. Instructions for updating can be found in the Contrast documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Edgelesssys Contrast | <= v1.17 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion