PT-2026-39556 · Go · Github.Com/Edgelesssys/Contrast

Publicado

2026-04-30

·

Atualizado

2026-04-30

CVSS v3.1

8.1

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Impact

The Kata agent policies generated by the Contrast CLI had an issue in the CopyFile verification, which allowed arbitrary writes to the guest root filesytem. A malicious process on the host with the capability to connect to the Kata agent VSOCK could connect to the agent and issue a series of CopyFile requests to overwrite security-critical files or trick the workload into disclosing sensitive data, which effectively amounts to a full guest takeover.

Patches

This issue has been patched in Contrast v1.19.1.
Note that this fix does not change the fact that host-provided content is generally not trustworthy, as documented.

Workarounds

If upgrading is not possible, users can implement the fix in rego and pass it to contrast generate --policy. The rego-only fix is a bit trickier than the patch, because the data to check is binary. See the references for details.

Resources

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-RH99-WC69-C255

Produtos afetados

Github.Com/Edgelesssys/Contrast