ACPI/AML Handling Vulnerability in Contrast Confidential Computing Runtime for Kubernetes
CVE-2026-100839

8.4HIGH

Key Information:

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100839?

The Contrast Confidential Computing Runtime for Kubernetes contains a vulnerability in the handling of the Advanced Configuration and Power Interface (ACPI) and ACPI Machine Language (AML) that exposes it to potential injection attacks. Specifically, in versions preceding 1.18.0, attackers could exploit this vulnerability by delivering crafted ACPI tables containing malicious AML bytecode from an untrusted host, such as QEMU, to the guest kernel. By taking control of the host, adversaries can execute arbitrary code within the guest environment, compromising the confidentiality of sensitive data residing in guest memory. This issue affects systems utilizing AMD SEV-SNP platforms, highlighting a critical flaw in the Confidential Computing model where the ACPI interface is improperly exposed. The release of version 1.18.0 addresses this vulnerability by implementing sandboxing measures for the AML interpreter, restricting its access to private memory pages.

Affected Version(s)

contrast 0 < 1.18.0

contrast 1.18.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

katexochen
sespiros
.