Description

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

INFO

Published Date :

2025-06-24T13:50:47.955Z

Last Modified :

2025-11-29T00:08:30.477Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-6032 vulnerability.

Vendors Products
Redhat
  • Enterprise Linux
  • Openshift
  • Rhel Eus

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact