Executive brief
Contrast is a runtime that allows Kubernetes to run confidential virtual machines on AMD and Intel platforms. An attacker with control over the host can inject malicious code into ACPI firmware tables, causing the guest kernel to execute arbitrary code with access to all guest memory. This results in complete compromise of confidential data running inside the protected VM.
Technical details
The vulnerability is an AML injection attack in the guest kernel's ACPI/AML interpreter. ACPI tables containing AML bytecode are passed from the host (QEMU) through firmware (OVMF) to the Linux kernel, where the AML interpreter executes them with access to full guest memory including private pages. An attacker with host-level control can craft malicious, Turing-complete AML bytecode to achieve arbitrary code execution and read/write confidential guest data. The fix sandboxes the AML interpreter to block private memory access via page table lookups.
Affected products
- Edgeless Systems Contrast before 1.18.0
Timeline
- 2026-03-24: disclosed
- 2026-09-27: advisory
- 2026-03-24: patched: v1.18.0