High severity8.6OSV Advisory· Published Apr 29, 2025· Updated Apr 15, 2026
CVE-2025-29906
CVE-2025-29906
Description
Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the tty configuration directive that can bypass /bin/login, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.
Affected products
1Patches
36528628b5c77185a72bd14d06528628b5c77Vulnerability mechanics
Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
2News mentions
0No linked articles in our index yet.