CVE-2025-6032: Podman: podman missing tls verification

Published Jun 12, 2025
·
Updated

Impact The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack.

Patches https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3 Fixed in v5.5.2

Workarounds Download the disk image manually via some other tool that verifies the TLS connection. Then pass the local image as file path (podman machine init --image ./somepath)

Other sources

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

NVD

The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack.

Requirements to exploit: Access to the network path between registry and client to perform a MITM attack.

Version affected: podman >= 4.8.0 Code was added in commit ea4775e, however it is only used as default way to pull images since 5.0.0.

Red Hat

Affected Software

3 affected componentsFixes available
Podman Podman>=4.8.0
go/github.com/containers/podman/v4>=4.8.0<=4.9.5
go/github.com/containers/podman/v5<5.5.2
5.5.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/containers/podman/v5 to a version that resolves this vulnerability.

    Fixed in 5.5.2
  2. Upgrade

    Upgrade Podman to a version that resolves this vulnerability.

    Fixed in 5.5.2
  3. Compensating control

    Avoid relying on podman machine init’s default OCI registry TLS verification; instead download the disk image manually using another tool that verifies the TLS connection, then pass the local image to podman machine init with --image ./somepath.

Event History

Jun 12, 2025
Data Sourced
via Red Hat·03:24 PM
DescriptionSeverityAffected Software
Jun 24, 2025
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Jun 25, 2025
Advisory Published
via GitHub·09:57 PM
Data Sourced
via GitHub·09:57 PM
DescriptionSeverityWeaknessAffected Software
Nov 16, 57490
Event
via FIRST·02:14 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-6032?

CVE-2025-6032 is considered a high severity vulnerability due to the potential for a Man In The Middle attack.

2

How do I fix CVE-2025-6032?

To fix CVE-2025-6032, upgrade Podman to version 5.5.2 or later.

3

Which versions of Podman are affected by CVE-2025-6032?

CVE-2025-6032 affects Podman versions from 4.8.0 up to 4.9.5.

4

What does CVE-2025-6032 affect in Podman?

CVE-2025-6032 affects the podman machine init command's failure to verify TLS certificates when downloading VM images.

5

What can happen if CVE-2025-6032 is exploited?

If CVE-2025-6032 is exploited, an attacker could intercept and manipulate VM images in a Man In The Middle attack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203