PT-2025-18214 · Finit+1 · Finit+1

·

CVE-2025-29906

·

Published

2025-03-18

·

Updated

2025-06-23

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Finit versions 3.0-rc1 through 4.11
Description Finit is a fast init for Linux systems. The issue concerns the implementation of getty for the tty configuration directive, which can bypass /bin/login, allowing a user to log in as any user without authentication. This can be exploited by manipulating the login prompt and requires access to the console. The problem has been patched in version 4.11.
Recommendations To resolve the issue, update to version 4.11 or later, as this version includes the patch for the authentication bypass issue. As a temporary workaround, consider restricting access to the console to minimize the risk of exploitation.

Exploit

Fix

LPE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05115
CVE-2025-29906
GHSA-563G-P98J-MC9Q

Affected Products

Debian
Finit