CVE-2026-100839 Overview
CVE-2026-100839 is an AML (ACPI Machine Language) injection vulnerability in Contrast, a confidential-computing runtime for Kubernetes developed by Edgeless Systems. The flaw, dubbed "BadAML," affects Contrast versions before 1.18.0 running on AMD SEV-SNP platforms (Metal-QEMU-SNP and Metal-QEMU-SNP-GPU). A malicious host can inject crafted AML bytecode through ACPI tables passed from QEMU to the guest firmware (OVMF) and ultimately to the Linux kernel's AML interpreter. The guest kernel executes this bytecode with full access to private guest memory, breaking the confidentiality guarantees of the trusted execution environment.
Critical Impact
An untrusted host can execute arbitrary code inside the confidential guest and read or modify private memory pages, defeating the core confidentiality and integrity guarantees of AMD SEV-SNP workloads [CWE-94].
Affected Products
- Contrast (Edgeless Systems) versions prior to 1.18.0
- Deployments on Metal-QEMU-SNP platform
- Deployments on Metal-QEMU-SNP-GPU platform
Discovery Timeline
- 2026-09-27 - CVE-2026-100839 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100839
Vulnerability Analysis
Contrast relies on AMD SEV-SNP to protect Kubernetes workloads from an untrusted host. The guest firmware (OVMF) accepts ACPI tables from QEMU during boot and forwards them to the Linux guest kernel. These tables contain AML bytecode, a Turing-complete interpreted language the kernel executes to configure hardware. On SEV-SNP, ACPI table contents are not measured into the attestation report, so a malicious host can substitute them without detection. The guest kernel's AML interpreter runs with kernel privileges and unrestricted access to private memory pages. Attackers abuse this capability to read secrets, modify data structures, or stage further code execution inside the confidential VM.
Root Cause
The vulnerability stems from the guest kernel treating host-supplied AML bytecode as trusted input [CWE-94]. The AML interpreter has no sandbox and can access the entire guest address space, including encrypted private pages. On Intel TDX, OVMF measures ACPI table contents into RTMR 0, which allows the guest to detect tampering. SEV-SNP lacks this measurement, so the Contrast threat model is violated when a malicious host crafts arbitrary AML.
Attack Vector
An attacker with control of the host hypervisor (QEMU) modifies ACPI tables delivered to the guest. The crafted AML bytecode is interpreted by the Linux kernel inside the confidential VM. Execution occurs during ACPI subsystem initialization or when AML methods are invoked at runtime. The attacker gains the ability to read private memory, overwrite kernel data, or hijack control flow. This weakness is generic to confidential computing designs that expose the ACPI interface to the host without measurement or sandboxing. See the GitHub Security Advisory GHSA-g9ww-x58f-9g6m for technical details.
Detection Methods for CVE-2026-100839
Indicators of Compromise
- Unexpected ACPI table modifications or non-standard DSDT/SSDT entries delivered by the host QEMU process
- Guest kernel log entries from the ACPI/AML subsystem referencing unknown methods, OperationRegions pointing to unusual physical addresses, or interpreter errors
- Anomalous memory read/write patterns originating from kernel ACPI handler contexts
Detection Strategies
- Compare ACPI tables presented to the guest against a known-good baseline captured from a trusted build
- Enable kernel ACPI debug logging (acpi.debug_level) in test environments to surface unexpected AML method invocations
- Audit Contrast runtime versions across the Kubernetes fleet and flag any node running a release earlier than 1.18.0
Monitoring Recommendations
- Collect guest kernel logs via Singularity Data Lake and alert on ACPI interpreter warnings or OperationRegion access to suspicious ranges
- Monitor Kubernetes admission events for pods scheduled on Metal-QEMU-SNP or Metal-QEMU-SNP-GPU nodes still running vulnerable Contrast releases
- Track attestation report contents and alert when a confidential node downgrades to an unexpected runtime version
How to Mitigate CVE-2026-100839
Immediate Actions Required
- Upgrade all Contrast deployments to version 1.18.0 or later, which sandboxes the kernel AML interpreter so it cannot read or write private memory pages
- Inventory confidential workloads running on AMD SEV-SNP and prioritize patching of Metal-QEMU-SNP and Metal-QEMU-SNP-GPU nodes
- Rotate any secrets that may have been processed inside unpatched confidential VMs where host trust cannot be established
Patch Information
Edgeless Systems released Contrast v1.18.0 to mitigate BadAML. The fix sandboxes the guest kernel's AML interpreter, restricting it from accessing private memory. Refer to the GitHub Security Advisory and the VulnCheck Security Advisory for release details.
Workarounds
- Migrate affected workloads to Metal-QEMU-TDX (Intel TDX), which is not affected because OVMF measures ACPI table contents into RTMR 0
- Restrict host-level access to the Kubernetes infrastructure hosting SEV-SNP guests until the Contrast runtime is upgraded
- Validate attestation reports before provisioning secrets to confidential VMs and reject nodes running Contrast versions earlier than 1.18.0
# Verify Contrast CLI and runtime version
contrast --version
# Upgrade Contrast to the patched release
contrast generate --reference-values metal-qemu-snp --image ghcr.io/edgelesssys/contrast:v1.18.0
kubectl apply -f runtime.yml
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.