CVE-2025-6032
published 2025-06-24CVE-2025-6032: A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue…
PriorityP340high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EPSS
0.40%
32.4th percentile
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpod | < podman 5.4.2+ds1-2 (forky) | podman 5.4.2+ds1-2 (forky) |
| debian | podman | < podman 5.4.2+ds1-2 (forky) | podman 5.4.2+ds1-2 (forky) |
| github.com | containers_podman_v4 | 4.8.0 – 4.9.5 | — |
| github.com | containers_podman_v4 | >= 4.8.0 | — |
| github.com | containers_podman_v5 | >= 0 < 5.5.2 | 5.5.2 |
| msrc | azl3_libcontainers-common_20240213-3_on_azure_linux_3.0 | — | — |
| podman_project | podman | >= 0 < 5.4.2+ds1-2 | 5.4.2+ds1-2 |
| podman_project | podman | >= 0 < 5.4.2+ds1-2 | 5.4.2+ds1-2 |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
osv8.3HIGH
vendor_debian8.3LOW
vendor_msrc8.3HIGH
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
podman: podman missing TLS verification
vendor_redhat·2025-06-24·CVSS 8.3
CVE-2025-6032 [HIGH] CWE-295 podman: podman missing TLS verification
podman: podman missing TLS verification
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
Statement: To exploit this flaw, a user needs to download an image from an untrusted OCI registry, specifically, an OCI registry with an invalid TLS certificate. This allows a remote attacker with access to the network path between the registry and the client to perform a Man In the Middle attack.
Mitigation: Download the VM image manually with another too
Microsoft
Podman: podman missing tls verification
vendor_msrc·2025-06-10·CVSS 8.3
CVE-2025-6032 [HIGH] CWE-295 Podman: podman missing tls verification
Podman: podman missing tls verification
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Debian
CVE-2025-6032: libpod - A flaw was found in Podman. The podman machine init command fails to verify the ...
vendor_debian·2025·CVSS 8.3
CVE-2025-6032 [HIGH] CVE-2025-6032: libpod - A flaw was found in Podman. The podman machine init command fails to verify the ...
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
Scope: local
bookworm: resolved
bullseye: resolved
OSV
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman
osv·2025-07-28
CVE-2025-6032 Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman
Podman Improper Certificate Validation; machine missing TLS verification in github.com/containers/podman
OSV
Podman Improper Certificate Validation; machine missing TLS verification
osv·2025-06-25
CVE-2025-6032 [HIGH] Podman Improper Certificate Validation; machine missing TLS verification
Podman Improper Certificate Validation; machine missing TLS verification
### Impact
The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack.
### Patches
https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3
Fixed in v5.5.2
### Workarounds
Download the disk image manually via some other tool that verifies the TLS connection. Then pass the local image as file path (podman machine init --image ./somepath)
GHSA
Podman Improper Certificate Validation; machine missing TLS verification
ghsa·2025-06-25
CVE-2025-6032 [HIGH] CWE-295 Podman Improper Certificate Validation; machine missing TLS verification
Podman Improper Certificate Validation; machine missing TLS verification
### Impact
The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack.
### Patches
https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3
Fixed in v5.5.2
### Workarounds
Download the disk image manually via some other tool that verifies the TLS connection. Then pass the local image as file path (podman machine init --image ./somepath)
OSV
CVE-2025-6032: A flaw was found in Podman
osv·2025-06-24·CVSS 8.3
CVE-2025-6032 [HIGH] CVE-2025-6032: A flaw was found in Podman
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2025:10295https://access.redhat.com/errata/RHSA-2025:10549https://access.redhat.com/errata/RHSA-2025:10550https://access.redhat.com/errata/RHSA-2025:10551https://access.redhat.com/errata/RHSA-2025:10668https://access.redhat.com/errata/RHSA-2025:11359https://access.redhat.com/errata/RHSA-2025:11363https://access.redhat.com/errata/RHSA-2025:11677https://access.redhat.com/errata/RHSA-2025:11681https://access.redhat.com/errata/RHSA-2025:15397https://access.redhat.com/errata/RHSA-2025:9726https://access.redhat.com/errata/RHSA-2025:9751https://access.redhat.com/errata/RHSA-2025:9766https://access.redhat.com/security/cve/CVE-2025-6032https://bugzilla.redhat.com/show_bug.cgi?id=2372501https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3https://github.com/containers/podman/security/advisories/GHSA-65gg-3w2w-hr4h
2025-06-24
Published