FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

podman -- TLS connection used to pull VM images was not validated

Affected packages
podman < 5.5.2

Details

VuXML ID 6b1b8989-55b0-11f0-ac64-589cfc10a551
Discovery 2025-06-30
Entry 2025-06-30

RedHat, Inc. reports:

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

References

CVE Name CVE-2025-6032
URL https://nvd.nist.gov/vuln/detail/CVE-2025-6032