First published: Tue Apr 29 2025(Updated: )
Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Finit | >=3.0-rc1<4.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29906 is a critical vulnerability as it allows users to log in without authentication.
To fix CVE-2025-29906, upgrade Finit to version 4.11 or later.
Finit versions starting from 3.0-rc1 up to, but not including, version 4.11 are affected by CVE-2025-29906.
Linux systems running the affected versions of Finit are at risk due to CVE-2025-29906.
CVE-2025-29906 compromises the authentication mechanism by allowing unauthorized access through the getty implementation.