CVE Vulnerabilities

CVE-2025-6032

Improper Certificate Validation

Published: Jun 24, 2025 | Modified: Jul 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.3 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat podman-6:5.4.0-12.el10_0 *
Red Hat Enterprise Linux 8 RedHat container-tools:rhel8-8100020250625105344.afee755d *
Red Hat Enterprise Linux 9 RedHat podman-5:5.4.0-12.el9_6 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat podman-4:4.9.4-18.el9_4.2 *
Red Hat OpenShift Container Platform 4.16 RedHat podman-4:4.9.4-16.rhaos4.16.el9 *
Red Hat OpenShift Container Platform 4.17 RedHat podman-5:5.2.2-8.rhaos4.17.el9 *
Red Hat OpenShift Container Platform 4.18 RedHat podman-5:5.2.2-9.rhaos4.18.el9 *
Red Hat OpenShift Container Platform 4.19 RedHat podman-5:5.4.0-6.rhaos4.19.el9 *

Potential Mitigations

References