VDB
Sign up
HIGH8.3

GHSA-65gg-3w2w-hr4h

Podman Improper Certificate Validation; machine missing TLS verification

Quick fix

GHSA-65gg-3w2w-hr4h — github.com/containers/podman/v5: upgrade to the fixed version with the command below.

go get github.com/containers/podman/v5@v5.5.2

Details

### Impact The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack.

### Patches https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3 Fixed in v5.5.2

### Workarounds Download the disk image manually via some other tool that verifies the TLS connection. Then pass the local image as file path (podman machine init --image ./somepath)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/containers/podman/v4
Introduced in: 4.8.0

No fixed version published yet for github.com/containers/podman/v4 (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/containers/podman/v5
Introduced in: 0Fixed in: 5.5.2
Fixgo get github.com/containers/podman/v5@v5.5.2

References