Junglewise Threat Intelligence

CVE-2025-71422: Edgeless Systems Contrast insecure LUKS2 persistent volume in initializer

CVE-2025-71422 · Severity: medium · CVSS 5.7 · Published 2026-09-27

Technologies: Edgeless Systems Contrast. Vendors: Edgeless Systems.

Executive brief

Contrast is a Kubernetes runtime that runs confidential workloads in isolated VMs with encrypted storage. A malicious host can provide a crafted disk volume with weak or null encryption that the Contrast guest will accept and use, exposing secret encryption keys and allowing the host to read all data written to that volume in plaintext. This affects encrypted persistent storage volumes that should protect sensitive application data.

Technical details

The Contrast Initializer uses cryptsetup to open encrypted persistent volumes, assuming success means the volume is protected. However, LUKS2 metadata is not authenticated and cryptsetup versions before 2.8.1 accept null-cipher keyslots without error. An attacker with control over the host storage can create a malicious LUKS2 volume with cipher_null-ecb that opens successfully with any passphrase, causing the guest to write secrets under an attacker-known or plaintext key. Fixed in Contrast v1.12.1 (upgrading cryptsetup to 2.8.1) and hardened further in v1.13.0 (detached-header validation and integrity protection).

Affected products

  • Edgeless Systems Contrast before 1.12.1

Timeline

  • 2025-10-27: disclosed
  • 2025-10-27: patched: v1.12.1 released with cryptsetup 2.8.1
  • 2025-10-27: patched: v1.13.0 released with detached-header validation and integrity protection

References

Related threats