Improper Verification of Cryptographic Signature
CVE-2025-58356
Summary
Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persistent storage. When opening an encrypted storage device, the CVM uses the 'libcryptsetup' function 'crypt_activate_by_passhrase'. If the VM is successful in opening the partition with the disk encryption key, it treats the volume as confidential. However, in versions prior to 2.24.0, due to the unsafe handling of null keyslot algorithms in the cryptsetup 2.8.1, it is possible that the opened volume is not encrypted at all. Cryptsetup prior to version 2.8.1 does not report an error when processing LUKS2-formatted disks that use the 'cipher_null-ecb' algorithm in the keyslot 'encryption' field. This vulnerability is fixed in 2.24.0.
- LOW
- LOCAL
- NONE
- HIGH
CWE-347 - Improper Verification of Cryptographic Signature
A cryptographic protocol is meant to ensure that services are provided in a secure manner. An application with absent or improper verification of cryptographic signatures allows malicious users to feed false messages to valid users or to disclose sensitive data, subverting the goals of the protocol. This can lead to security failures such as false authentication, account hijacking, and privilege escalation.
References
Advisory Timeline
- Published