Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-6032

Опубликовано: 24 июн. 2025
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

Отчет

To exploit this flaw, a user needs to download an image from an untrusted OCI registry, specifically, an OCI registry with an invalid TLS certificate. This allows a remote attacker with access to the network path between the registry and the client to perform a Man In the Middle attack.

Меры по смягчению последствий

Download the VM image manually with another tool that verifies the TLS certificate and then pass the local image as a file path to podman, for example:

podman machine init --image

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10podmanFixedRHSA-2025:1054908.07.2025
Red Hat Enterprise Linux 8container-toolsFixedRHSA-2025:1055108.07.2025
Red Hat Enterprise Linux 9podmanFixedRHSA-2025:1055008.07.2025
Red Hat Enterprise Linux 9.4 Extended Update SupportpodmanFixedRHSA-2025:1066808.07.2025
Red Hat OpenShift Container Platform 4.16podmanFixedRHSA-2025:976602.07.2025
Red Hat OpenShift Container Platform 4.16rhcos-416.94.202507222002FixedRHSA-2025:1168130.07.2025
Red Hat OpenShift Container Platform 4.17podmanFixedRHSA-2025:1029509.07.2025
Red Hat OpenShift Container Platform 4.18rhcos-418.94.202507221927FixedRHSA-2025:1167730.07.2025
Red Hat OpenShift Container Platform 4.18podmanFixedRHSA-2025:972602.07.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2372501podman: podman missing TLS verification

EPSS

Процентиль: 14%
0.00046
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
7 месяцев назад

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

CVSS3: 8.3
nvd
7 месяцев назад

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

msrc
5 месяцев назад

Podman: podman missing tls verification

CVSS3: 8.3
debian
7 месяцев назад

A flaw was found in Podman. The podman machine init command fails to v ...

suse-cvrf
5 месяцев назад

Security update for podman

EPSS

Процентиль: 14%
0.00046
Низкий

8.3 High

CVSS3