Contrast 是专为 Kubernetes 设计的机密计算运行时环境。在 1.18.0 版本之前,客户机内核的 ACPI/AML(高级配置与电源接口/ACPI 机器语言)处理模块易受 AML 注入攻击(称为“BadAML”)。包含 AML 字节码的 ACPI 表从不可信的主机(QEMU)传递到客户机固件(OVMF),进而传递给 Linux 内核,由其 AML 解释器执行这些字节码。攻击者若能控制主机(在 Contrast 的威胁模型中,主机被视为假设的敌对实体),就可以构造一个包含恶意、图灵完备 AML 字节码
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| edgelesssys | contrast | 0 ~ 1.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100833 | 8.2 HIGH | Contrast before 1.23.1 Image Substitution via Policy Generation |
| CVE-2026-100838 | 8.1 HIGH | Contrast before 1.19.1 CopyFile Policy Symlink Subversion |
| CVE-2026-100835 | 7.4 HIGH | Contrast before 1.16.0 Remote Attestation Relay Attack |
| CVE-2025-71425 | 7.3 HIGH | Contrast before 1.8.1 Information Disclosure via Logging |
| CVE-2025-71423 | 7.3 HIGH | Edgelesssys Contrast before 1.12.2 Workload Secrets Information Disclosure |
| CVE-2025-71426 | 7.1 HIGH | Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery |
| CVE-2025-71422 | 5.7 MEDIUM | Contrast before 1.12.1 Insecure LUKS2 Persistent Storage |
| CVE-2026-100836 | 4.3 MEDIUM | Edgeless Systems Contrast through 1.20.0 Denial of Service via ciphertextContainer |
| CVE-2026-100837 | 3.7 LOW | Edgeless Systems Contrast through 1.20.0 Credential Leak via Registry Suffix Matching |
| CVE-2025-71424 | 3.5 LOW | Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount |
No comments yet