CVE-2025-71424: Edgeless Systems Contrast before 1.9.1 Insecure Volume Mount
Contrast, Edgeless Systems' runtime for confidential containers on Kubernetes, is affected in versions up to and including 1.9.0. The VOLUME directive in a Dockerfile (config.volumes in the OCI image configuration) is only a hint and is not handled specially by Kubernetes, but containerd adds a mount point for it when Kubernetes sets none, requiring the runtime to be able to push arbitrary data to the Kata agent. As a result, on bare-metal Contrast deployments (AKS deployments are not affected) that run an image declaring at least one VOLUME for which no Kubernetes mount exists at that path, the untrusted host can write arbitrary file trees below that mount point inside the confidential container, compromising the integrity of a directory that is typically important to the application's core functionality. Version 1.9.1 fixes the issue by disallowing this configuration in contrast generate.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Edgeless Systems Contrastto a version that resolves this vulnerability.Fixed in 1.9.1
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Bare-metal Contrast deployments running versions through 1.9.0 are affected when an image declares at least one VOLUME path that has no corresponding Kubernetes mount. AKS deployments are not affected.
What does an attacker need to exploit it?
The untrusted host must be able to act against a confidential container meeting the affected image and mount configuration. Exploitation relies on an image-declared VOLUME for which Kubernetes does not provide a mount at the same path.
What can the attacker do in an affected deployment?
The untrusted host can write arbitrary file trees beneath the affected mount point inside the confidential container. This compromises the integrity of a directory that is typically important to the application's core functionality.
How can I determine whether a workload is affected?
Check whether Contrast is version 1.9.0 or earlier on bare metal, then inspect the image OCI configuration or Dockerfile for VOLUME declarations. A workload is affected when Kubernetes does not define a mount at one or more of those declared paths.
What remediation is available?
Upgrade to Contrast 1.9.1. This version causes contrast generate to reject the unsafe configuration.