CVE-2015-3246

Red Hat Libuser: Race Condition

As of , CVE-2015-3246 in Red Hat Libuser is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 26 August 2026
US federal deadline
9 September 202614 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.08Higher than 94% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
Public exploit
1 Metasploit module and 2 Exploit-DB entries (2 verified)
Fix
Vendor advice: access.redhat.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA's required action

What the flaw is

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

CISA's description

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

The CVE record's description, from redhat

CVE published
11 August 2015
Assigned by
redhat
CVSS
7.4 High (CVSS 3.1, from CISA-ADP)
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
CISA SSVC, exploitation
active
CISA SSVC, automatable
no
CISA SSVC, technical impact
total

Timeline

  1. Exploit-DB published an exploit (EDB-ID 37706).
  2. The CVE record was published.
  3. Exploit-DB published an exploit (EDB-ID 44633).
  4. CISA added it to its list of exploited vulnerabilities.
  5. The US federal deadline to fix it.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Read further