HIGH CISA-KEV ACTIVELY EXPLOITED

CVE-2015-3246

Red Hat Libuser Race Condition Vulnerability

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

Affected Products

References

Published: 2026-08-26 · Source: CISA-KEV · Feed updated: 2026-08-26
This high severity vulnerability was published on 2026-08-26 via CISA-KEV. ⚠ This vulnerability is in the CISA Known Exploited Vulnerabilities (KEV) catalog — it is being actively exploited in the wild. EPSS score: 7.1% (top 6% of all CVEs by exploitation probability). Affected: Red Hat: Libuser.

Risk Timeline

CVE Disclosed2026-08-26 · 0 days ago
CISA KEV — Actively ExploitedU.S. federal agencies required to patch · confirmed threat-actor activity

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2015-5287 KEVRed Hat Automatic Bug Reporting Tool Privilege Escalation VulnerabilityHIGH
vulnfeed aggregates 11128 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.