Sceawere
Vulnerability Detail
CVE-2026-100839UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Contrast AML Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.4
- Creation Date
- 1d ago
- Vendor
- edgelesssys
- Product
- contrast
- Attack Type
- Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware (OVMF) and on to the Linux kernel, whose AML interpreter executes them. An attacker controlling the host — an assumed adversary in Contrast's threat model — can craft a table with malicious, Turing-complete AML bytecode that the guest kernel interprets with access to the full guest memory, including private pages, resulting in arbitrary code execution and disclosure or modification of confidential guest data. The issue affects the AMD SEV-SNP platforms Metal-QEMU-SNP and Metal-QEMU-SNP-GPU; Metal-QEMU-TDX is not affected because ACPI table contents are measured into RTMR 0 by OVMF on Intel TDX. Version v1.18.0 mitigates the attack by sandboxing the kernel AML interpreter so that it cannot read or write private memory pages. This weakness is not specific to Contrast but is generic to Confidential Computing setups that expose the ACPI interface to the host.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.4",
"pubDate": "2026-09-27T02:17:22.230Z",
"pubdate": "2026-09-27T02:17:22.230Z",
"executiveSummary": "The Contrast confidential-computing runtime is susceptible to an AML injection vulnerability, designated as BadAML, affecting versions prior to 1.18.0. This vulnerability arises from the insecure handling of ACPI/AML bytecode provided by the host environment to the guest kernel.\nIn the Contrast threat model, the host (QEMU) is considered an untrusted adversary. By crafting malicious ACPI tables containing Turing-complete AML bytecode, an attacker can trigger execution within the guest kernel's AML interpreter. Because this interpreter operates with excessive privileges, the attacker gains the ability to access, modify, or exfiltrate private guest memory pages.\nThe vulnerability specifically impacts AMD SEV-SNP platforms, including Metal-QEMU-SNP and Metal-QEMU-SNP-GPU, as these configurations pass ACPI tables into the guest without sufficient validation or measurement. Intel TDX configurations are protected by the measurement of ACPI tables into the RTMR 0 register. This flaw represents a critical security risk to the confidentiality and integrity of the guest runtime, potentially leading to complete system compromise if successfully exploited.\nThe vulnerability highlights a systemic risk in Confidential Computing where ACPI interfaces are exposed to potentially malicious host environments without hardware-backed integrity validation.",
"technicalDetails": "The root cause of this vulnerability is the lack of sandboxing and memory isolation for the Linux kernel's AML interpreter when processing ACPI tables provided by the untrusted host. In the affected versions of Contrast (prior to 1.18.0), the kernel consumes ACPI tables directly from the host-managed QEMU interface. The kernel's AML interpreter, which is Turing-complete, executes bytecode provided in these tables to perform firmware-related initialization and power management tasks.\nThe attack flow initiates when the malicious host injects a crafted ACPI table into the guest. The OVMF firmware passes this structure to the guest Linux kernel. Upon initialization or during triggered ACPI events, the kernel's AML interpreter parses and executes the malicious bytecode. Since the interpreter historically executes with the same privilege level as the kernel itself, it possesses the capability to perform arbitrary memory reads and writes across the entire guest address space, including memory protected by SEV-SNP encryption.\nExploitation allows an adversary to bypass Confidential Computing protections by manipulating kernel data structures, stealing cryptographic keys, or injecting malicious code into kernel memory space. By leveraging the interpreter's ability to interface with system memory, an attacker can bypass memory encryption boundaries enforced by the AMD SEV-SNP hardware, as the interpreter runs within the guest's execution context and effectively holds the keys to the guest's private memory pages.\nThis issue is not confined to a single implementation but reflects a generic architectural weakness where host-to-guest ACPI communication channels lack the necessary hardware-rooted trust or rigorous validation required for a Confidential Computing environment. Versions prior to 1.18.0 fail to implement strict boundary controls for the interpreter. Version 1.18.0 introduces mandatory sandboxing, which restricts the interpreter's access, preventing it from performing unauthorized operations on private memory pages regardless of the malicious input provided by the host."
}