CVE-2025-6032: Red Hat Enterprise Linux 10
High severity, CVSS 8.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 6:5.4.0-12.el10_0 (fixed in 6:5.4.0-12.el10_0)
- Red Hat Red Hat Enterprise Linux 8: before 8100020250625105344.afee755d (fixed in 8100020250625105344.afee755d)
- Red Hat Red Hat Enterprise Linux 9: before 5:5.4.0-12.el9_6 (fixed in 5:5.4.0-12.el9_6)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 4:4.9.4-18.el9_4.2 (fixed in 4:4.9.4-18.el9_4.2)
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Openshift Container Platform 4.16: before 4:4.9.4-14.rhaos4.16.el8 (fixed in 4:4.9.4-14.rhaos4.16.el8); before 416.94.202507222002-0 (fixed in 416.94.202507222002-0)
- Red Hat Red Hat Openshift Container Platform 4.17: before 5:5.2.2-8.rhaos4.17.el8 (fixed in 5:5.2.2-8.rhaos4.17.el8); before 417.94.202507132309-0 (fixed in 417.94.202507132309-0)
- Red Hat Red Hat Openshift Container Platform 4.18: before 418.94.202507221927-0 (fixed in 418.94.202507221927-0); before 5:5.2.2-9.rhaos4.18.el9 (fixed in 5:5.2.2-9.rhaos4.18.el9)
- Red Hat Red Hat Openshift Container Platform 4.19: before 4.19.9.6.202507152218-0 (fixed in 4.19.9.6.202507152218-0); before 5:5.4.0-6.rhaos4.19.el9 (fixed in 5:5.4.0-6.rhaos4.19.el9)
- Red Hat Red Hat Openshift Container Platform 4.20: before 4.20.9.6.202509251656-0 (fixed in 4.20.9.6.202509251656-0)
Published 2025-06-24. Last modified 2026-08-31.