CVE-2025-71422
Last modified
CVE-2025-71422 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM.
Description
Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM. LUKS2 volume metadata is not authenticated and, with cryptsetup versions prior to 2.8.1, a header specifying the null keyslot encryption algorithm (cipher_null-ecb) is accepted without error. Because the Contrast Initializer assumes a device is protected if `cryptsetup open` succeeds with the secret seed, the guest will open the attacker-supplied volume and write secret data in plaintext, or under a volume key known to the attacker, allowing the host to read confidential data that should have been encrypted. Contrast v1.12.1 ships cryptsetup 2.8.1, which disables null ciphers in keyslots when the passphrase is non-empty; v1.13.0 adds detached-header validation in guest memory and integrity protection for secure persistent storage. Contrast persistent volumes were not integrity protected, so integrity impact is not considered.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| edgelesssys | contrast | < 1.12.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2025-71422?
How severe is CVE-2025-71422?
How do I fix CVE-2025-71422?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-71417PocketMine-MP before 5.32.1 fails to validate uniqueness of …6.5
- CVE-2025-71418PocketMine-MP versions before 5.25.2 fail to limit the explo…5.3
- CVE-2025-71419UVdesk core-framework before 1.1.7 contains a stored cross-s…5.4
- CVE-2025-7142A vulnerability, which was classified as problematic, has be…5.4
- CVE-2025-71420UVdesk core-framework before 1.1.7 contains an authorization…4.3
- CVE-2025-71421UVdesk core-framework before 1.1.7 contains an improper priv…7.2
- CVE-2025-71423Edgelesssys Contrast is a confidential-computing runtime for…7.3
- CVE-2025-71424Contrast, Edgeless Systems' runtime for confidential contain…3.5
- CVE-2025-71425Contrast (Edgeless Systems) before 1.8.1 logs the workload s…7.3
- CVE-2025-71426Contrast is a confidential-computing runtime for Kubernetes.…7.1
- CVE-2025-7143A vulnerability, which was classified as problematic, was fo…5.4
- CVE-2025-7144A vulnerability has been found in SourceCodester Best Salon …4.8
Are you affected by CVE-2025-71422?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
