CISA added CVE-2015-3246, a race condition in Red Hat's libuser library, to the Known Exploited Vulnerabilities catalog on 2026-08-26 with a remediation deadline of 2026-09-09.
What Is It
libuser before 0.56.13-8, and 0.60 before 0.60-7, directly modifies /etc/passwd rather than writing atomically. As used in the userhelper program from the usermode package, this allows a local user to trigger an error mid-modification and leave /etc/passwd in an inconsistent state; a denial of service. NVD tracks it under CWE-264 (primary) and CWE-367, Time-of-check Time-of-use race condition (secondary). NVD's CVSS v3.1 score is 5.1 (MEDIUM), vector AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H.
Why It Matters
CISA's KEV listing confirms active exploitation, and CISA's SSVC assessment marks exploitation as "active" with automatable "no" and technical impact "partial." Known ransomware campaign use is listed as Unknown.
The MEDIUM severity rating likely understates the operational risk. Per NVD, this issue can be combined with CVE-2015-3245 to gain privileges; corrupting /etc/passwd is arguably not merely a stability problem when it can be chained into local privilege escalation. Public exploit material exists: NVD references a Qualys write-up covering both CVEs and an Exploit-DB entry.
What's Vulnerable
- Red Hat Enterprise Linux 5, 6, and 7
- openSUSE 13.2
- libuser versions before 0.56.13-8, and 0.60 up to (excluding) 0.60-7
CISA notes this affects an open-source component that may be bundled by other products, so inventory beyond the CPEs above.
Patch Status
Vendor fixes shipped in 2015 via RHSA-2015-1482 and RHSA-2015-1483, with an openSUSE advisory alongside. Red Hat also published mitigation guidance at access.redhat.com/articles/1537873.
CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. Due date: 2026-09-09.
Sources
- CISA KEV Catalog Entry; https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- NVD, CVE-2015-3246, https://nvd.nist.gov/vuln/detail/CVE-2015-3246
- Red Hat Mitigation Article; https://access.redhat.com/articles/1537873
- RHSA-2015-1482; http://rhn.redhat.com/errata/RHSA-2015-1482.html
- RHSA-2015-1483; http://rhn.redhat.com/errata/RHSA-2015-1483.html
- openSUSE Security Announce; http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html
- Qualys Advisory (CVE-2015-3245 / CVE-2015-3246), https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt
- Exploit-DB 44633; https://www.exploit-db.com/exploits/44633/
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk