ZeroDayAlert

CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

Red Hat Libuser Added to KEV 2026-08-26 Federal due 2026-09-09 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Red Hat Libuser is a user and group management library used by system administration tools and services. The vulnerability affects deployments where authenticated local users can reach the Libuser code path—typically Linux systems where Libuser is installed as a dependency of administrative utilities. The record does not specify which versions of Libuser are vulnerable, nor does it name the dependent products most commonly affected.

How to check whether this touches you

  • Inventory whether Libuser is installed on your Linux systems: run rpm -qa | grep libuser (Red Hat/CentOS) or dpkg -l | grep libuser (Debian/Ubuntu).
  • Establish which local user accounts exist and whether they have legitimate administrative or service roles; this vulnerability requires authenticated local access.
  • Query your configuration management or asset database to identify systems where you cannot easily patch or where patching cycles are long.
  • Check the Red Hat Security Advisories portal for the specific affected version range and any errata linked to this CVE, as backported fixes may exist in your deployed version even if the base version number appears old.

What to do

  1. Contact your Red Hat support channel or check the Red Hat security errata feed for CVE-2015-3246 to confirm the patched version and any interim mitigations Red Hat has published.
  2. If you cannot patch immediately, audit /etc/passwd file permissions and monitor for unexpected modifications; restrict local shell access to users who require administrative privileges.
  3. Prioritise patching in line with BOD 26-04 guidance: systems exposed to untrusted local users (such as shared hosting or multi-tenant platforms) should be treated as higher risk.
  4. Apply the vendor patch or update when ready; test in a non-production environment first if your change control process requires it.
  5. Document the date patched and the version applied, and verify that the patch was successful before closing the ticket.

If you find you were exposed

Exploitation of a race condition in /etc/passwd corruption is difficult to detect retrospectively without detailed audit logs, because the attack window is narrow and the damage is overwriting a system file. Review your system logs (auth logs, file integrity monitoring alerts) for the period before you became aware of the vulnerability, focusing on failed authentication attempts or unexpected privilege escalation. If you retain logs for longer than 90 days, search for suspicious calls to Libuser functions or repeated failed writes to /etc/passwd.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2015-3246 is being exploited. It cannot tell you whether Libuser is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →