CVE-2025-6032

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
Configurations

No configuration.

History

02 Jul 2025, 08:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9726 -
  • () https://access.redhat.com/errata/RHSA-2025:9766 -

01 Jul 2025, 08:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:9751 -

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) Se detectó una falla en Podman. El comando podman machine init no verifica el certificado TLS al descargar imágenes de máquinas virtuales desde un registro OCI. Este problema provoca un ataque de intermediario (Man in the Middle).

24 Jun 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 14:15

Updated : 2025-07-02 08:15


NVD link : CVE-2025-6032

Mitre link : CVE-2025-6032

CVE.ORG link : CVE-2025-6032


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation