Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-32022— Finit has heap based buffer overwrite in urandom.so plugin

Quick assessment

Affected
troglobit finit
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

finit是Joachim Wiberg个人开发者的一个Linux的快速初始化工具。 finit 4.2及之后版本存在缓冲区错误漏洞,该漏洞源于urandom插件存在堆缓冲区覆盖,可能导致随机不稳定和未定义行为。

CVSS 4.6 · Medium EPSS 0.14% · P4
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-32022

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Finit has heap based buffer overwrite in urandom.so plugin
Source: CVE Program / CVE List V5
Vulnerability Description
Finit provides fast init for Linux systems. Finit's urandom plugin has a heap buffer overwrite vulnerability at boot which leads to it overwriting other parts of the heap, possibly causing random instabilities and undefined behavior. The urandom plugin is enabled by default, so this bug affects everyone using Finit 4.2 or later that do not explicitly disable the plugin at build time. This bug is fixed in Finit 4.12. Those who cannot upgrade or backport the fix to urandom.c are strongly recommended to disable the plugin in the call to the `configure` script.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5
Vulnerability Title
finit 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
finit是Joachim Wiberg个人开发者的一个Linux的快速初始化工具。 finit 4.2及之后版本存在缓冲区错误漏洞,该漏洞源于urandom插件存在堆缓冲区覆盖,可能导致随机不稳定和未定义行为。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
troglobit finit >= 4.2, < 4.12 -

II. Public POCs for CVE-2025-32022

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-32022

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-32022

No comments yet


Leave a comment