Skip to main content
QUIETLYTIC
Vulnerability

libuser Vulnerability (CVE-2015-3246)

CVE-2015-3246 is a CVSS 5.1 race condition in libuser affecting /etc/passwd, confirmed exploited per CISA KEV.

CVE-2015-3246
Threat Level
MEDIUM
CVSS
5.1
Status
Active Exploitation
Confidence
High
Affected Products
libuser (before 0.56.13-8, and 0.60 before 0.60-7)

CVE-2015-3246 carries a CVSS 3.1 base score of 5.1 against libuser, the library behind the userhelper program in the usermode package, before version 0.56.13-8 and 0.60 before 0.60-7. NVD classifies it as CWE-264/CWE-367 (Permissions, Privileges, and Access Control / Time-of-Check Time-of-Use Race Condition). CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 26, 2026, confirming real-world exploitation directly rather than through a single vendor report.

Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.

What the flaw is

NVD’s description states that libuser directly modifies /etc/passwd, and a race condition in that modification can cause a denial of service — an inconsistent file state — if an error occurs during the write. NVD’s own note is explicit that this issue can be combined with a related flaw, CVE-2015-3245, to escalate from that denial-of-service condition to privilege gain. We have not yet published a separate advisory on CVE-2015-3245; we mention the combination here only because NVD’s own record states it, not as a claim we have independently analyzed that second CVE.

Evidence and confidence

  • High confidence — exploitation status, sourced directly to CISA’s own Known Exploited Vulnerabilities catalog.
  • Medium confidence — the CVSS 5.1 score, vector (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H), and CWE-264/CWE-367 classification, which trace to NVD alone in our current ingestion.
  • Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.08799, a 94.9th percentile score as of our ingestion — a striking figure for a decade-old CVE, consistent with its recent KEV addition.

No field is in conflict between our sources. This CVE dates to 2015 but was only added to CISA’s KEV catalog in August 2026, more than a decade after initial disclosure — a reminder that KEV listing tracks confirmed exploitation activity, not recency of discovery.

Why this matters

A race condition that corrupts /etc/passwd is a local denial-of-service issue on its own, but NVD’s explicit note that it chains with CVE-2015-3245 into a privilege-gain path is the operative detail here — this is not a standalone low-severity bug but one half of an escalation chain. Systems still running an unpatched libuser more than a decade after the original 2015 disclosure represent exactly the kind of long-tail legacy exposure that a fresh KEV listing surfaces: old, forgotten, and still reachable by local users.

Frequently Asked Questions

What is CVE-2015-3246? A CVSS 5.1 race-condition vulnerability (CWE-264/CWE-367) in libuser before 0.56.13-8 (and 0.60 before 0.60-7), where a race during a direct write to /etc/passwd can corrupt the file’s state, and which NVD notes can be chained with CVE-2015-3245 to gain privileges.

Is CVE-2015-3246 being actively exploited? Yes, per CISA’s Known Exploited Vulnerabilities catalog, which added it on August 26, 2026.

Do I need an account to exploit this? The CVSS vector specifies a local attack vector with no privileges required (AV:L, PR:N), meaning an attacker needs local access to the system but not an elevated account.

Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.

Which versions fix this? libuser 0.56.13-8 and later, and 0.60-7 and later, per NVD’s description. Red Hat’s own errata (RHSA-2015-1482 and RHSA-2015-1483) cover the fix.


Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2015-3246. Exploitation status and the August 26, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry. Fix references: Red Hat RHSA-2015:1482 and RHSA-2015:1483. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog
03 VulnCheck KEV

Related intelligence


Analyst tools