Vault Misconfiguration in Constellation's Confidential Kubernetes by Edgeless Systems
CVE-2025-58356

8.3HIGH

Key Information:

Vendor
CVE Published:
27 October 2025

What is CVE-2025-58356?

In Constellation's implementation of Kubernetes, a flaw exists in the handling of LUKS2-encrypted storage volumes due to the use of cryptsetup versions older than 2.24.0. When activating a partition with the disk encryption key, there is a risk that the volume treated as confidential may actually remain unencrypted if the cipher_null-ecb algorithm is incorrectly processed. This oversight leads to potential exposure of sensitive data stored on these volumes, emphasizing the critical need to upgrade to the patched version to ensure data integrity and confidentiality.

Affected Version(s)

constellation < 2.24.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.