CVE Vulnerabilities

CVE-2025-6032

Improper Certificate Validation

Published: Jun 24, 2025 | Modified: Nov 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.3 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatpodman-6:5.4.0-12.el10_0*
Red Hat Enterprise Linux 8RedHatcontainer-tools:rhel8-8100020250625105344.afee755d*
Red Hat Enterprise Linux 9RedHatpodman-5:5.4.0-12.el9_6*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatpodman-4:4.9.4-18.el9_4.2*
Red Hat OpenShift Container Platform 4.16RedHatpodman-4:4.9.4-16.rhaos4.16.el9*
Red Hat OpenShift Container Platform 4.16RedHatrhcos-416.94.202507222002-0*
Red Hat OpenShift Container Platform 4.17RedHatpodman-5:5.2.2-8.rhaos4.17.el8*
Red Hat OpenShift Container Platform 4.17RedHatrhcos-417.94.202507132309-0*
Red Hat OpenShift Container Platform 4.18RedHatrhcos-418.94.202507221927-0*
Red Hat OpenShift Container Platform 4.18RedHatpodman-5:5.2.2-9.rhaos4.18.el9*
Red Hat OpenShift Container Platform 4.19RedHatrhcos-4.19.9.6.202507152218-0*
Red Hat OpenShift Container Platform 4.19RedHatpodman-5:5.4.0-6.rhaos4.19.el9*
Red Hat OpenShift Container Platform 4.20RedHatrhcos-4.20.9.6.202509251656-0*
PodmanUbuntuplucky*

Potential Mitigations

References