Multiple vulnerabilities were discovered in the use of LUKS2 disk encryption within confidential computing systems, allowing attackers with write access to storage disks to extract or modify confidential data. These flaws stem from malleable metadata headers in LUKS2, which can be exploited to trick trusted execution environment (TEE) guests into encrypting data with a null cipher, effectively disabling encryption. The vulnerabilities impact several confidential computing frameworks, including Edgeless Constellation, and are tracked under CVE-2025-59054 and CVE-2025-58356. Affected projects have released patches, and users are advised to update to the latest versions and ensure remote attestation reports reject pre-patch versions.
Specifically, the Constellation Confidential Kubernetes platform was found to allow insecure use of LUKS2-encrypted persistent storage partitions. Due to unsafe handling of null keyslot algorithms in cryptsetup versions prior to 2.8.1, Constellation's CVM image could treat unencrypted volumes as confidential, exposing sensitive data. The vulnerability is addressed in Constellation version 2.24.0 and cryptsetup 2.8.1. There is no evidence of exploitation in the wild, but organizations using these frameworks should apply mitigations immediately to prevent potential data compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Trail of Bits published technical details about vulnerabilities in LUKS2 disk encryption for confidential VMs, expanding public information about the weakness. The post indicates broader technical disclosure related to the insecure use of LUKS2 in this context.
A high-severity vulnerability, CVE-2025-58356, was published describing that Constellation allows insecure use of LUKS2 persistent storage partitions. This appears to be the first public disclosure of the issue in the provided references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.