BlackTree Security · Infrastructure · Automation · AI

Three Ways the Host Can Cross Contrast’s Confidential Boundary

Confidential computing assumes the cloud host may be hostile. Three previously disclosed Contrast vulnerabilities show how easily that promise can be weakened when identity, file operations or firmware data still cross from the untrusted side.

The primary advisories were published between March and July 2026. They returned to the discovery queue because NVD, NVD and NVD published their public records on 27 September. That is delayed indexing, not a new disclosure and not evidence of exploitation.

A valid attestation report did not identify the machine

CVE-2026-100835 concerns remote attestation before Contrast 1.16.0. According to the vendor advisory, Contrast accepted a correctly signed report with expected firmware and software measurements without binding it to a specific physically trusted machine.

The attestation advisory requires substantial attacker capabilities: interception between the command-line client and coordinator, or between the coordinator and workload, plus a forged report or secrets extracted from a controlled trusted-execution machine. If those conditions are met, the report can be relayed to impersonate a coordinator or workload inside Contrast’s attested TLS.

The practical lesson is about what attestation proves. A genuine statement about code and firmware is not automatically a statement that this particular workload is speaking from the intended physical system.

A permitted copy operation became a guest takeover

CVE-2026-100838, fixed in Contrast 1.19.1, affects Kata agent policies generated by the Contrast command-line tool. The primary advisory says the policy’s CopyFile verification allowed an untrusted host process with access to the Kata agent VSOCK to perform arbitrary writes into the guest root filesystem.

The CopyFile advisory says overwriting a security-critical file can alter what starts inside the confidential guest, while carefully chosen paths may also expose data. That turns a management operation into effective guest takeover even though the memory-encryption technology itself has not been broken.

The firmware interface carried executable input from the host

CVE-2026-100839 is the BadAML issue fixed in Contrast 1.18.0. The vendor advisory explains that ACPI tables supplied by QEMU can contain AML bytecode that the guest kernel interprets. A malicious host can craft that input to execute with access to private guest memory.

The BadAML advisory covers Contrast platforms using AMD SEV-SNP with QEMU, including the GPU variant. It says the Intel TDX platform is not affected because OVMF measures the ACPI table contents into RTMR 0. Contrast 1.18.0 mitigates the AMD path by sandboxing the AML interpreter so it cannot read or write private pages.

What operators should verify

  • Move to Contrast 1.19.1 or later. That includes the software fixes for the CopyFile and BadAML paths, but it does not by itself repair the attestation threat model.
  • Bind attestation to trusted hardware. The vendor requires workload owners to populate AllowedChipIDs for AMD SEV-SNP or AllowedPIIDs for Intel TDX using identifiers gathered from physically trusted hardware.
  • Regenerate policies. Upgrading a binary without replacing generated Kata policy can leave an old trust decision in place.
  • Map the platform. Identify AMD SEV-SNP workloads, Kata agent VSOCK exposure and coordinator communication paths.
  • Monitor host-to-guest management traffic. Unexpected CopyFile operations or ACPI changes belong in the detection model for a hostile host.
  • Assume the control plane is part of the boundary. The cryptographic TEE cannot compensate for every unsafe policy or firmware interface surrounding it.

BlackTree previously examined how Apple moved its Private Cloud Compute trust model onto Google’s hardware. Contrast exposes the same strategic problem from another direction: confidential computing is a chain of measured code, hardware identity, policy generation and carefully constrained interfaces. The chain is only as strong as the parts the untrusted host can still influence.

The reviewed Contrast advisories do not report exploitation in the wild. Their value is architectural: each provides a reusable example of how a threat model can fail without defeating the underlying memory-encryption primitive.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *