PT-2026-99445 · Containerd+3 · Kubernetes Containerd+3

·

CVE-2025-71424

·

Published

2025-07-09

·

Updated

2026-09-28

CVSS v4.0

5.1

Medium

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Contrast versions prior to 1.9.1
Description On bare-metal deployments, an untrusted host can write arbitrary file trees below a mount point inside a confidential container if the image declares at least one VOLUME (specified via the config.volumes in the OCI image configuration) for which no Kubernetes mount exists. This occurs because containerd adds a mount point when Kubernetes sets none, allowing the runtime to push data to the Kata agent, which compromises the integrity of directories critical to application functionality.
Recommendations Update to version 1.9.1, which disallows this configuration in contrast generate.

Exploit

Fix

Files Accessible to External Parties

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71424
GHSA-PHHQ-63JG-FP7R
GO-2025-3807

Affected Products

Contrast
Kata
Kubernetes
Kubernetes Containerd