Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the tty configuration directive that can bypass /bin/login, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.
{
"cwe_ids": [
"CWE-287"
]
}[
{
"source": "https://github.com/finit-project/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "exec_login",
"file": "src/getty.c"
},
"id": "CVE-2025-29906-4f9ecd9c",
"digest": {
"length": 563.0,
"function_hash": "119575122103930956426117148705173701036"
},
"signature_type": "Function"
},
{
"source": "https://github.com/finit-project/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "src/getty.c"
},
"id": "CVE-2025-29906-53bc0c9f",
"digest": {
"threshold": 0.9,
"line_hashes": [
"105929115891636115889017790541775814200",
"98118360729421153779944852331474853756",
"70882017660745328739545150808633831783",
"156921722014421408919646958253466209069",
"235550450089593423843841550145511010691",
"166078352421179977899414920107781009171"
]
},
"signature_type": "Line"
}
]