Red Hat · Libuser
CVE-2015-3246
Red Hat Libuser Race Condition Vulnerability
CISA KEV record
- CISA date added
- 2026-08-26
- CISA due date
- 2026-09-09
- Known ransomware use
- Unknown
NVD risk context
5.1 MEDIUM
CVSS is a technical severity score. CISA’s KEV status remains the evidence that this vulnerability is known to be exploited.
Description
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD reference index
Vendor and remediation references
NVD has tagged these sources as vendor advisories, patches, mitigations, or release notes.
- http://rhn.redhat.com/errata/RHSA-2015-1482.html ↗
- http://rhn.redhat.com/errata/RHSA-2015-1483.html ↗
- https://access.redhat.com/articles/1537873 ↗
Other NVD references (9)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.html ↗
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.html ↗
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html ↗
- http://www.securityfocus.com/bid/76022 ↗
- http://www.securitytracker.com/id/1033040 ↗
- https://www.exploit-db.com/exploits/44633/ ↗
- https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt ↗
- https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/ ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3246 ↗
MITRE CWE context
CWE classification
CISA has not listed a CWE classification for this entry.
NVD record timing
NVD record timeline
These dates describe NVD’s record, not CISA’s KEV addition or remediation due date.
- NVD published
- Aug 11, 2015, 02:59 PM UTC When NVD first published this CVE record.
- NVD last updated
- Aug 27, 2026, 04:16 AM UTC When NVD last changed its analysis or record data.
Advanced: view the technical CVSS vector
This standardized code is intended for security tools and technical analysts. The plain-language risk summary above explains its main points.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA notes
This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://access.redhat.com/articles/1537873 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3246
- https://access.redhat.com/articles/1537873
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://nvd.nist.gov/vuln/detail/CVE-2015-3246