CVE-2025-32022 – Finit Urandom Heap Buffer Overwrite Vulnerability

The following table lists the changes that have been made to the
CVE-2025-32022 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 06, 2025

    Action Type Old Value New Value
    Added Description Finit provides fast init for Linux systems. Finit’s urandom plugin has a heap buffer overwrite vulnerability at boot which leads to it overwriting other parts of the heap, possibly causing random instabilities and undefined behavior. The urandom plugin is enabled by default, so this bug affects everyone using Finit 4.2 or later that do not explicitly disable the plugin at build time. This bug is fixed in Finit 4.12. Those who cannot upgrade or backport the fix to urandom.c are strongly recommended to disable the plugin in the call to the `configure` script.
    Added CVSS V3.1 AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:L
    Added CWE CWE-787
    Added Reference https://github.com/troglobit/finit/commit/3feff37ba51fa0a6a0a06f59682a0918aa5b04de
    Added Reference https://github.com/troglobit/finit/security/advisories/GHSA-fv6v-vw8h-9×79
Share the Post:

Related Posts