CVE-2025-6032

Aliases:GHSA-65gg-3w2w-hr4hGO-2025-3777DEBIAN-CVE-2025-6032RHSA-2025:10549RHSA-2025:10550RHSA-2025:10551RHSA-2025:10668RHSA-2025:9726RHSA-2025:9751RHSA-2025:9766CGA-6hjf-987v-57h3CGA-9438-5mpv-2gmqCGA-h9cc-mxf4-85gfCGA-j79h-hjjv-h2r4
Deferred
Published: 24 Jun 2025, 13:50
Last modified:31 Aug 2026, 16:50

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.3 HIGH
v3.1 (cve.org)
EPSS Score
0.48% LOW
0% probability +0.43%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Jun 2025, 13:50
Published
Vulnerability first disclosed
31 Aug 2026, 16:50
Last Modified
Vulnerability information updated

Description

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

CVSS Metrics

  • v3.1HIGHScore: 8.3CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.48% Percentile: 41%

Techniques & Countermeasures

  • CWE-295Improper Certificate Validation

    The product does not validate, or incorrectly validates, a certificate.

Affected Systems

  • chainguardprometheus-podman-exporter

    < 1.17.1-r1

  • chainguardprometheus-podman-exporter-fips

    < 1.17.1-r1

  • debianpodman

    < 5.4.2+ds1-2 | < 5.4.2+ds1-2

  • github.com/containerspodman

    all

  • github.com/containers/podmanv2

    all

  • github.com/containers/podmanv3

    all

  • github.com/containers/podmanv4

    ≥ 4.8.0 | ≥ 4.8.0, ≤ 4.9.5

  • github.com/containers/podmanv5

    < 5.5.2

  • redhataardvark-dns

    < 2:1.10.1-2.module+el8.10.0+23320+f7205097

  • redhatbuildah

    < 2:1.33.12-2.module+el8.10.0+23320+f7205097

  • redhatbuildah-debuginfo

    < 2:1.33.12-2.module+el8.10.0+23320+f7205097

  • redhatbuildah-debugsource

    < 2:1.33.12-2.module+el8.10.0+23320+f7205097

  • redhatbuildah-tests

    < 2:1.33.12-2.module+el8.10.0+23320+f7205097

  • redhatbuildah-tests-debuginfo

    < 2:1.33.12-2.module+el8.10.0+23320+f7205097

  • redhatcockpit-podman

    < 0:84.1-1.module+el8.10.0+23320+f7205097

  • redhatconmon

    < 3:2.1.10-1.module+el8.10.0+23320+f7205097

  • redhatconmon-debuginfo

    < 3:2.1.10-1.module+el8.10.0+23320+f7205097

  • redhatconmon-debugsource

    < 3:2.1.10-1.module+el8.10.0+23320+f7205097

  • redhatcontainer-selinux

    < 2:2.229.0-2.module+el8.10.0+23320+f7205097

  • redhatcontainernetworking-plugins

    < 1:1.4.0-6.module+el8.10.0+23320+f7205097

  • redhatcontainernetworking-plugins-debuginfo

    < 1:1.4.0-6.module+el8.10.0+23320+f7205097

  • redhatcontainernetworking-plugins-debugsource

    < 1:1.4.0-6.module+el8.10.0+23320+f7205097

  • redhatcontainers-common

    < 2:1-82.module+el8.10.0+23320+f7205097

  • redhatcrit

    < 0:3.18-5.module+el8.10.0+23320+f7205097

  • redhatcriu

    < 0:3.18-5.module+el8.10.0+23320+f7205097

  • redhatcriu-debuginfo

    < 0:3.18-5.module+el8.10.0+23320+f7205097

  • redhatcriu-debugsource

    < 0:3.18-5.module+el8.10.0+23320+f7205097

  • redhatcriu-devel

    < 0:3.18-5.module+el8.10.0+23320+f7205097

  • redhatcriu-libs

    < 0:3.18-5.module+el8.10.0+23320+f7205097

  • redhatcriu-libs-debuginfo

    < 0:3.18-5.module+el8.10.0+23320+f7205097

  • redhatcrun

    < 0:1.14.3-2.module+el8.10.0+23320+f7205097

  • redhatcrun-debuginfo

    < 0:1.14.3-2.module+el8.10.0+23320+f7205097

  • redhatcrun-debugsource

    < 0:1.14.3-2.module+el8.10.0+23320+f7205097

  • redhatfuse-overlayfs

    < 0:1.13-1.module+el8.10.0+23320+f7205097

  • redhatfuse-overlayfs-debuginfo

    < 0:1.13-1.module+el8.10.0+23320+f7205097

  • redhatfuse-overlayfs-debugsource

    < 0:1.13-1.module+el8.10.0+23320+f7205097

  • redhatlibslirp

    < 0:4.4.0-2.module+el8.10.0+23320+f7205097

  • redhatlibslirp-debuginfo

    < 0:4.4.0-2.module+el8.10.0+23320+f7205097

  • redhatlibslirp-debugsource

    < 0:4.4.0-2.module+el8.10.0+23320+f7205097

  • redhatlibslirp-devel

    < 0:4.4.0-2.module+el8.10.0+23320+f7205097

  • redhatnetavark

    < 2:1.10.3-1.module+el8.10.0+23320+f7205097

  • redhatoci-seccomp-bpf-hook

    < 0:1.2.10-1.module+el8.10.0+23320+f7205097

  • redhatoci-seccomp-bpf-hook-debuginfo

    < 0:1.2.10-1.module+el8.10.0+23320+f7205097

  • redhatoci-seccomp-bpf-hook-debugsource

    < 0:1.2.10-1.module+el8.10.0+23320+f7205097

  • redhatpodman

    < 6:5.4.0-12.el10_0 | < 5:5.4.0-12.el9_6 | < 4:4.9.4-22.module+el8.10.0+23320+f7205097 | < 4:4.9.4-18.el9_4.2 | < 5:5.2.2-9.rhaos4.18.el9 | < 5:5.4.0-6.rhaos4.19.el9 | < 4:4.9.4-14.rhaos4.16.el8 | < 4:4.9.4-16.rhaos4.16.el9

  • redhatpodman-catatonit

    < 4:4.9.4-22.module+el8.10.0+23320+f7205097 | < 4:4.9.4-14.rhaos4.16.el8

  • redhatpodman-catatonit-debuginfo

    < 4:4.9.4-22.module+el8.10.0+23320+f7205097 | < 4:4.9.4-14.rhaos4.16.el8

  • redhatpodman-debuginfo

    < 6:5.4.0-12.el10_0 | < 5:5.4.0-12.el9_6 | < 4:4.9.4-22.module+el8.10.0+23320+f7205097 | < 4:4.9.4-18.el9_4.2 | < 5:5.2.2-9.rhaos4.18.el9 | < 5:5.4.0-6.rhaos4.19.el9 | < 4:4.9.4-14.rhaos4.16.el8 | < 4:4.9.4-16.rhaos4.16.el9

  • redhatpodman-debugsource

    < 6:5.4.0-12.el10_0 | < 5:5.4.0-12.el9_6 | < 4:4.9.4-22.module+el8.10.0+23320+f7205097 | < 4:4.9.4-18.el9_4.2 | < 5:5.2.2-9.rhaos4.18.el9 | < 5:5.4.0-6.rhaos4.19.el9 | < 4:4.9.4-14.rhaos4.16.el8 | < 4:4.9.4-16.rhaos4.16.el9

  • redhatpodman-docker

    < 6:5.4.0-12.el10_0 | < 5:5.4.0-12.el9_6 | < 4:4.9.4-22.module+el8.10.0+23320+f7205097 | < 4:4.9.4-18.el9_4.2 | < 5:5.2.2-9.rhaos4.18.el9 | < 5:5.4.0-6.rhaos4.19.el9 | < 4:4.9.4-14.rhaos4.16.el8 | < 4:4.9.4-16.rhaos4.16.el9

Showing first 50 affected entries in server-rendered view.

References (33)