CVE-2025-29906 Information
Apr 30, 2025
cve
Description
Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the tty configuration directive that can bypass /bin/login i.e. a user can log in as any user without authentication. This issue has been patched in version 4.11.
Reference
https://github.com/troglobit/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0 https://github.com/troglobit/finit/security/advisories/GHSA-563g-p98j-mc9q
Share on: