Описание
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
Отчет
To exploit this flaw, a user needs to download an image from an untrusted OCI registry, specifically, an OCI registry with an invalid TLS certificate. This allows a remote attacker with access to the network path between the registry and the client to perform a Man In the Middle attack.
Меры по смягчению последствий
Download the VM image manually with another tool that verifies the TLS certificate and then pass the local image as a file path to podman, for example:
podman machine init --image
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenShift Container Platform 4 | rhcos | Affected | ||
Red Hat Enterprise Linux 10 | podman | Fixed | RHSA-2025:10549 | 08.07.2025 |
Red Hat Enterprise Linux 8 | container-tools | Fixed | RHSA-2025:10551 | 08.07.2025 |
Red Hat Enterprise Linux 9 | podman | Fixed | RHSA-2025:10550 | 08.07.2025 |
Red Hat Enterprise Linux 9.4 Extended Update Support | podman | Fixed | RHSA-2025:10668 | 08.07.2025 |
Red Hat OpenShift Container Platform 4.16 | podman | Fixed | RHSA-2025:9766 | 02.07.2025 |
Red Hat OpenShift Container Platform 4.17 | podman | Fixed | RHSA-2025:10295 | 09.07.2025 |
Red Hat OpenShift Container Platform 4.18 | podman | Fixed | RHSA-2025:9726 | 02.07.2025 |
Red Hat OpenShift Container Platform 4.19 | podman | Fixed | RHSA-2025:9751 | 01.07.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.3 High
CVSS3
Связанные уязвимости
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
A flaw was found in Podman. The podman machine init command fails to v ...
Podman Improper Certificate Validation; machine missing TLS verification
ELSA-2025-10551: container-tools:rhel8 security update (IMPORTANT)
EPSS
8.3 High
CVSS3