ACPI/AML Handling Vulnerability in Contrast Confidential Computing Runtime for Kubernetes
CVE-2026-100839
What is CVE-2026-100839?
The Contrast Confidential Computing Runtime for Kubernetes contains a vulnerability in the handling of the Advanced Configuration and Power Interface (ACPI) and ACPI Machine Language (AML) that exposes it to potential injection attacks. Specifically, in versions preceding 1.18.0, attackers could exploit this vulnerability by delivering crafted ACPI tables containing malicious AML bytecode from an untrusted host, such as QEMU, to the guest kernel. By taking control of the host, adversaries can execute arbitrary code within the guest environment, compromising the confidentiality of sensitive data residing in guest memory. This issue affects systems utilizing AMD SEV-SNP platforms, highlighting a critical flaw in the Confidential Computing model where the ACPI interface is improperly exposed. The release of version 1.18.0 addresses this vulnerability by implementing sandboxing measures for the AML interpreter, restricting its access to private memory pages.
Affected Version(s)
contrast 0 < 1.18.0
contrast 1.18.0
