HIGH 8.3 Go
Podman Improper Certificate Validation; machine missing TLS verification
GHSA-65gg-3w2w-hr4h · CVE-2025-6032 · GO-2025-3777
Published · Modified
Description
Impact
The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack.
Patches
https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3
Fixed in v5.5.2
Workarounds
Download the disk image manually via some other tool that verifies the TLS connection. Then pass the local image as file path (podman machine init --image ./somepath)
References
- WEB https://github.com/containers/podman/security/advisories/GHSA-65gg-3w2w-hr4h
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-6032
- WEB https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3
- PACKAGE https://github.com/containers/podman
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2372501
- WEB https://access.redhat.com/security/cve/CVE-2025-6032
- WEB https://access.redhat.com/errata/RHSA-2025:9766
- WEB https://access.redhat.com/errata/RHSA-2025:9751
- WEB https://access.redhat.com/errata/RHSA-2025:9726
- WEB https://access.redhat.com/errata/RHSA-2025:15397
- WEB https://access.redhat.com/errata/RHSA-2025:11681
- WEB https://access.redhat.com/errata/RHSA-2025:11677
- WEB https://access.redhat.com/errata/RHSA-2025:11363
- WEB https://access.redhat.com/errata/RHSA-2025:11359
- WEB https://access.redhat.com/errata/RHSA-2025:10668
- WEB https://access.redhat.com/errata/RHSA-2025:10551
- WEB https://access.redhat.com/errata/RHSA-2025:10550
- WEB https://access.redhat.com/errata/RHSA-2025:10549
- WEB https://access.redhat.com/errata/RHSA-2025:10295
Ready to move
Start Securing
Free, no credit card | First findings in minutes