Vault Misconfiguration in Constellation's Confidential Kubernetes by Edgeless Systems
CVE-2025-58356
8.3HIGH
What is CVE-2025-58356?
In Constellation's implementation of Kubernetes, a flaw exists in the handling of LUKS2-encrypted storage volumes due to the use of cryptsetup versions older than 2.24.0. When activating a partition with the disk encryption key, there is a risk that the volume treated as confidential may actually remain unencrypted if the cipher_null-ecb algorithm is incorrectly processed. This oversight leads to potential exposure of sensitive data stored on these volumes, emphasizing the critical need to upgrade to the patched version to ensure data integrity and confidentiality.
Affected Version(s)
constellation < 2.24.0
