{"id":"CVE-2025-29906","summary":"Finit bundled getty can bypass /bin/login","details":"Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.","aliases":["GHSA-563g-p98j-mc9q"],"modified":"2026-08-12T15:16:23.092424Z","published":"2025-04-29T22:17:47.228Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29906.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29906.json"},{"type":"ADVISORY","url":"https://github.com/troglobit/finit/security/advisories/GHSA-563g-p98j-mc9q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-29906"},{"type":"FIX","url":"https://github.com/troglobit/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/finit-project/finit","events":[{"introduced":"dd566acfd2b8f182ec1a930c979843072e4b2564"},{"fixed":"6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0"}],"database_specific":{"extracted_events":[{"introduced":"3.0-rc1"},{"fixed":"4.11"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["4.10","4.10-rc2","4.10-rc1","4.9","4.9-rc1","4.8","4.7","4.6","4.5","4.5-rc5","4.5-rc4","4.5-rc3","4.5-rc2","4.5-rc1","4.4","4.4-rc2","4.4-rc1","4.3","4.3-rc2","4.3-rc1","4.2","4.1","4.1-rc2","4.1-rc1","4.0","4.0-rc4","4.0-rc2","4.0-rc1","3.2-rc3","3.2-rc2","3.2-rc1","3.1","3.1-rc2","3.1-rc1","3.0","3.0-rc2","3.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29906.json","vanir_signatures_modified":"2026-08-12T15:16:23Z","vanir_signatures":[{"target":{"file":"src/getty.c","function":"exec_login"},"deprecated":false,"digest":{"function_hash":"119575122103930956426117148705173701036","length":563},"id":"CVE-2025-29906-4f9ecd9c","signature_type":"Function","signature_version":"v1","source":"https://github.com/finit-project/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0"},{"deprecated":false,"digest":{"line_hashes":["105929115891636115889017790541775814200","98118360729421153779944852331474853756","70882017660745328739545150808633831783","156921722014421408919646958253466209069","235550450089593423843841550145511010691","166078352421179977899414920107781009171"],"threshold":0.9},"id":"CVE-2025-29906-53bc0c9f","signature_type":"Line","signature_version":"v1","source":"https://github.com/finit-project/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0","target":{"file":"src/getty.c"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}