UBUNTU-CVE-2025-29906

Source
https://ubuntu.com/security/CVE-2025-29906
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-29906.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2025-29906
Related
Published
2025-04-29T23:16:00Z
Modified
2025-04-30T16:30:26Z
Summary
[none]
Details

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the tty configuration directive that can bypass /bin/login, i.e., a user can log in as any user without authentication. This issue has been patched in version 4.11.

References

Affected packages

Ubuntu:22.04:LTS / finit

Package

Name
finit
Purl
pkg:deb/ubuntu/finit@4.2-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.1-1
4.2-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / finit

Package

Name
finit
Purl
pkg:deb/ubuntu/finit@4.7-2?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.7-1build2
4.7-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / finit

Package

Name
finit
Purl
pkg:deb/ubuntu/finit@4.7-1build2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.2-1
4.7-1
4.7-1build1
4.7-1build2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:25.04 / finit

Package

Name
finit
Purl
pkg:deb/ubuntu/finit@4.7-3?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.7-2
4.7-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}