Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-71422— Contrast before 1.12.1 Insecure LUKS2 Persistent Storage

Quick assessment

Affected
edgelesssys contrast
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contrast 是一个用于机密容器的 Kubernetes 运行时环境。在 1.12.1 版本之前,其安全持久卷(secure persistent volume)功能存在漏洞:恶意主机可向 Pod 虚拟机(pod VM)提供精心构造的 LUKS2 卷。由于 LUKS2 卷元数据未进行身份验证,且在 cryptsetup 2.8.1 之前的版本中,系统会无报错地接受使用空密钥槽加密算法(cipher_null-ecb)的头部信息。Contrast Initializer 模块在 使用秘密种子(secret see

CVSS 5.7 · Medium EPSS 0.07% · P0

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-71422

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Contrast before 1.12.1 Insecure LUKS2 Persistent Storage
Source: CVE Program / CVE List V5
Vulnerability Description
Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM. LUKS2 volume metadata is not authenticated and, with cryptsetup versions prior to 2.8.1, a header specifying the null keyslot encryption algorithm (cipher_null-ecb) is accepted without error. Because the Contrast Initializer assumes a device is protected if `cryptsetup open` succeeds with the secret seed, the guest will open the attacker-supplied volume and write secret data in plaintext, or under a volume key known to the attacker, allowing the host to read confidential data that should have been encrypted. Contrast v1.12.1 ships cryptsetup 2.8.1, which disables null ciphers in keyslots when the passphrase is non-empty; v1.13.0 adds detached-header validation in guest memory and integrity protection for secure persistent storage. Contrast persistent volumes were not integrity protected, so integrity impact is not considered.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
密码学签名的验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
edgelesssys contrast 0 ~ 1.12.1 -

II. Public POCs for CVE-2025-71422

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-71422

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-71422 (1)

Other References for CVE-2025-71422 (1)

Same Patch Batch · edgelesssys · 2026-09-27 · 11 CVEs total

CVE-2026-100839 8.4 HIGH Contrast before 1.18.0 AML Injection Remote Code Execution
CVE-2026-100833 8.2 HIGH Contrast before 1.23.1 Image Substitution via Policy Generation
CVE-2026-100838 8.1 HIGH Contrast before 1.19.1 CopyFile Policy Symlink Subversion
CVE-2026-100835 7.4 HIGH Contrast before 1.16.0 Remote Attestation Relay Attack
CVE-2025-71425 7.3 HIGH Contrast before 1.8.1 Information Disclosure via Logging
CVE-2025-71423 7.3 HIGH Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
CVE-2025-71426 7.1 HIGH Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
CVE-2026-100836 4.3 MEDIUM Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer
CVE-2026-100837 3.7 LOW Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
CVE-2025-71424 3.5 LOW Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount

IV. Related Vulnerabilities

V. Comments for CVE-2025-71422

No comments yet


Leave a comment