The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack. Requirements to exploit: Access to the network path between registry and client to perform a MITM attack. Version affected: podman >= 4.8.0 Code was added in commit ea4775e, however it is only used as default way to pull images since 5.0.0.
Just noting that the code with the issue was first introduced in Podman v4.8 and RHEL 8.10 & 9.4. Also in OCP 4.16. Earlier versions of OCP and RHEL are not affected by this issue.
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2025:9751 https://access.redhat.com/errata/RHSA-2025:9751
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2025:9726 https://access.redhat.com/errata/RHSA-2025:9726
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:9766 https://access.redhat.com/errata/RHSA-2025:9766
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:10549 https://access.redhat.com/errata/RHSA-2025:10549
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:10550 https://access.redhat.com/errata/RHSA-2025:10550
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:10551 https://access.redhat.com/errata/RHSA-2025:10551
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:10668 https://access.redhat.com/errata/RHSA-2025:10668
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:10295 https://access.redhat.com/errata/RHSA-2025:10295
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.19 Via RHSA-2025:11363 https://access.redhat.com/errata/RHSA-2025:11363
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.17 Via RHSA-2025:11359 https://access.redhat.com/errata/RHSA-2025:11359
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.16 Via RHSA-2025:11681 https://access.redhat.com/errata/RHSA-2025:11681
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.18 Via RHSA-2025:11677 https://access.redhat.com/errata/RHSA-2025:11677