Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

[KEV] CVE-2015-3246 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2015-3246 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2015-3246 is a race condition in Red Hat Libuser that can be exploited by an authenticated local user during account-management operations to corrupt the system’s /etc/passwd file.

Technical Detail

The flaw arises from unsafe concurrent handling of updates to /etc/passwd by Libuser. An authenticated local attacker can race a Libuser operation to alter or corrupt password-file contents. Successful exploitation can cause a denial of service by rendering account data unusable and may allow local privilege escalation, depending on the resulting file contents and system configuration.

Exploitation Status

Exploit maturity is assessed as Operational, meaning exploitation methods are sufficiently developed for practical use by attackers with local authenticated access. CISA has confirmed active exploitation in the wild. This CVE was added to the Known Exploited Vulnerabilities Catalog on August 26, 2026.

Who Is Targeting This

No specific threat actor attribution at this time.

What To Do

Prioritize installation of the applicable Red Hat Libuser security updates and verify that all affected systems have received the vendor-provided fix. Federal civilian executive branch agencies must patch by the CISA-specified due date or apply mitigations in accordance with CISA Binding Operational Directive 22-01; the due date is not included in the available data. Where immediate patching is not possible, restrict interactive local access to trusted users, limit access to account-management utilities, and closely monitor changes to /etc/passwd, /etc/shadow, and related account databases. Review system logs for unexpected user or group administration activity and maintain verified backups of account files to support recovery from corruption.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →