← CVE Tracker
7.4HIGHCISA KEV — actively exploited

CVE-2015-3246 — Red Hat Libuser Race Condition Vulnerability

Red Hat · Libuser · Published 26 Aug 2026 · Modified 2 Oct 2026

Description

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

References

What to do
  1. Check whether Libuser is in your asset inventory.
  2. Exploitation confirmed — patch within 72 hours.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2015-3246