Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100839— Contrast before 1.18.0 AML Injection Remote Code Execution

Quick assessment

Affected
edgelesssys contrast
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Contrast 是专为 Kubernetes 设计的机密计算运行时环境。在 1.18.0 版本之前,客户机内核的 ACPI/AML(高级配置与电源接口/ACPI 机器语言)处理模块易受 AML 注入攻击(称为“BadAML”)。包含 AML 字节码的 ACPI 表从不可信的主机(QEMU)传递到客户机固件(OVMF),进而传递给 Linux 内核,由其 AML 解释器执行这些字节码。攻击者若能控制主机(在 Contrast 的威胁模型中,主机被视为假设的敌对实体),就可以构造一个包含恶意、图灵完备 AML 字节码

CVSS 8.4 · High EPSS 0.15% · P3
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100839

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Contrast before 1.18.0 AML Injection Remote Code Execution
Source: CVE Program / CVE List V5
Vulnerability Description
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware (OVMF) and on to the Linux kernel, whose AML interpreter executes them. An attacker controlling the host — an assumed adversary in Contrast's threat model — can craft a table with malicious, Turing-complete AML bytecode that the guest kernel interprets with access to the full guest memory, including private pages, resulting in arbitrary code execution and disclosure or modification of confidential guest data. The issue affects the AMD SEV-SNP platforms Metal-QEMU-SNP and Metal-QEMU-SNP-GPU; Metal-QEMU-TDX is not affected because ACPI table contents are measured into RTMR 0 by OVMF on Intel TDX. Version v1.18.0 mitigates the attack by sandboxing the kernel AML interpreter so that it cannot read or write private memory pages. This weakness is not specific to Contrast but is generic to Confidential Computing setups that expose the ACPI interface to the host.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
edgelesssys contrast 0 ~ 1.18.0 -

II. Public POCs for CVE-2026-100839

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100839

请登录查看更多情报信息。

News Coverage for CVE-2026-100839 (1)

Other References for CVE-2026-100839 (1)

Same Patch Batch · edgelesssys · 2026-09-27 · 11 CVEs total

CVE-2026-100833 8.2 HIGH Contrast before 1.23.1 Image Substitution via Policy Generation
CVE-2026-100838 8.1 HIGH Contrast before 1.19.1 CopyFile Policy Symlink Subversion
CVE-2026-100835 7.4 HIGH Contrast before 1.16.0 Remote Attestation Relay Attack
CVE-2025-71425 7.3 HIGH Contrast before 1.8.1 Information Disclosure via Logging
CVE-2025-71423 7.3 HIGH Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure
CVE-2025-71426 7.1 HIGH Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
CVE-2025-71422 5.7 MEDIUM Contrast before 1.12.1 Insecure LUKS2 Persistent Storage
CVE-2026-100836 4.3 MEDIUM Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer
CVE-2026-100837 3.7 LOW Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching
CVE-2025-71424 3.5 LOW Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount

IV. Related Vulnerabilities

V. Comments for CVE-2026-100839

No comments yet


Leave a comment