PT-2026-99443 · Contrast+1 · Contrast+1

·

CVE-2025-71422

·

Published

2025-10-28

·

Updated

2026-09-27

CVSS v4.0

6.9

Medium

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Contrast versions prior to 1.12.1
Description The secure persistent volume feature is susceptible to an attack where a malicious host provides a crafted LUKS2 volume to a pod VM. This occurs because LUKS2 volume metadata is not authenticated and cryptsetup versions prior to 2.8.1 accept a header specifying the null keyslot encryption algorithm (cipher null-ecb) without error. The Contrast Initializer assumes a device is protected if the cryptsetup open function succeeds with the secret seed. Consequently, the guest may open the attacker-supplied volume and write secret data in plaintext or using a volume key known to the attacker, enabling the host to read confidential data.
Recommendations Update to version 1.12.1 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71422
GHSA-F5P4-P5Q5-JV3H
GO-2025-4078

Affected Products

Contrast
Cryptsetup