Threat+Constellation
Live UTC
← Incidents
INCIDENT 281Exploited vulnerabilityHIGH CONFIDENCESourced

CVE-2015-3246 added to CISA KEV: Red Hat Libuser Race Condition Vulnerability

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

Last evidence update
26 AUG 2026 · 00:00 UTC
Source count
4
Status
high confidence
LogisticsCVE-2015-3246CVE-2015-5287CVE-2015-3245
Observation history

How this record has evolved as evidence accumulated.

27 AUG · 05:21 UTC
Initial report
27 AUG · 05:21 UTC
Second independent source
27 AUG · 05:21 UTC
Related CVE identified (CVE-2015-5287)
27 AUG · 05:21 UTC
Second independent source
27 AUG · 05:21 UTC
Summary updated from new evidence
27 AUG · 05:21 UTC
Confidence upgraded
27 AUG · 05:21 UTC
Status changed
27 AUG · 05:21 UTC
Related CVE identified (CVE-2015-3245)
27 AUG · 05:21 UTC
Second independent source
Evidence
Related incidents