CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability
Summary
A race condition vulnerability in Red Hat libuser (CVE-2015-3246) allows authenticated local users to corrupt the /etc/passwd file, potentially leading to denial of service or privilege escalation. Organizations are advised to apply vendor-provided mitigations and comply with CISA's guidance on prioritizing security updates.
IFF Assessment
This vulnerability allows for privilege escalation or denial of service, which are detrimental to system security.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 09, 2026. Known ransomware use: Unknown.
Defender Context
This CVE highlights a persistent vulnerability that could be exploited for privilege escalation. Defenders should ensure systems are patched and that access controls are robust to prevent local users from exploiting such flaws. The mention of "Known ransomware use: Unknown" also underscores the importance of proactive patching against potential future exploitation.