CVE-2025-6032 describes a critical vulnerability in Podman where the 'podman machine init' command fails to validate TLS certificates when downloading VM images from OCI registries. This flaw enables a Man-in-the-Middle (MITM) attack, allowing an attacker to intercept and potentially manipulate the downloaded images. With a CVSS score of 8.3 (HIGH), the vulnerability has a network attack vector, high impact on confidentiality, integrity, and availability, and requires user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat Enterprise Linux 9 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4 | All Versions ImpactedCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | Range not provided by sourceCNA affecteddefault affected | |
| Red Hat | Red Hat OpenShift Container Platform 4.17 | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.