Edgeless Constellation CVM images use LUKS2-encrypted volumes for persistent storage and rely on libcryptsetup to open those volumes. In the vulnerable design, the CVM calls crypt_activate_by_passphrase and, if activation succeeds with the disk-encryption key, treats the resulting volume as confidential. Due to unsafe handling of null keyslot algorithms in cryptsetup prior to the fixed Constellation release, LUKS2 metadata can be crafted so that a disk using the cipher_null-ecb algorithm in the keyslot encryption field is accepted without error. Because cipher_null-ecb is effectively an identity transform, a maliciously modified LUKS2 header can cause the guest to accept a volume that is not meaningfully encrypted while still appearing valid to the CVM. More broadly, this is part of a class of issues involving malleable LUKS2 metadata headers in confidential VM environments, where an attacker with write access to the backing disk can alter header parameters and subvert confidentiality guarantees.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.