CVE-2025-29906

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.
Configurations

No configuration.

History

29 Apr 2025, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 23:16

Updated : 2025-04-29 23:16


NVD link : CVE-2025-29906

Mitre link : CVE-2025-29906

CVE.ORG link : CVE-2025-29906


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication