Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the tty configuration directive that can bypass /bin/login, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-287"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29906.json"
}[
{
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2025-29906-4f9ecd9c",
"target": {
"file": "src/getty.c",
"function": "exec_login"
},
"digest": {
"length": 563.0,
"function_hash": "119575122103930956426117148705173701036"
},
"signature_version": "v1",
"source": "https://github.com/finit-project/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0"
},
{
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2025-29906-53bc0c9f",
"target": {
"file": "src/getty.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"105929115891636115889017790541775814200",
"98118360729421153779944852331474853756",
"70882017660745328739545150808633831783",
"156921722014421408919646958253466209069",
"235550450089593423843841550145511010691",
"166078352421179977899414920107781009171"
]
},
"signature_version": "v1",
"source": "https://github.com/finit-project/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29906.json"