All incidents

CISA adds Red Hat libuser race condition flaw (CVE-2015-3246) to KEV catalogue

vulnerabilityopenAug 26, 2026 — Aug 27, 2026

CISA has added CVE-2015-3246 to its Known Exploited Vulnerabilities catalogue, signalling that the flaw is being actively exploited in the wild. The entry was posted on the KEV site on 26 August 2026 and references the Red Hat libuser race condition. This addition means that federal civilian agencies and private sector organisations using affected systems must prioritise remediation. The catalogue is designed to help defenders focus on vulnerabilities that pose the greatest immediate risk.

The vulnerability is identified as CVE-2015-3246 and carries a CVSS v3.1 base score of 5.1, rated MEDIUM. It resides in the libuser library, a component used for managing user and group accounts on Red Hat based Linux distributions. A race condition exists between the time a temporary file is created and when it is renamed, allowing an authenticated local user to manipulate the operation. By exploiting this window, an attacker can overwrite or corrupt critical system files such as /etc/passwd, leading to denial of service or privilege escalation.

Red Hat addressed the issue in an advisory available at Red Hat advisory, which provides updated libuser packages that eliminate the race condition. The fix is included in libuser version 0.56.17-1.el6_7 and later releases across the supported product lines. Systems running older releases remain exposed and should be upgraded as soon as a maintenance window allows. The advisory also lists the exact RPM names for Red Hat Enterprise Linux 6 and 7, as well as for derived distributions.

CISA's decision to list CVE-2015-3246 was based on telemetry showing that the flaw has been observed in exploitation attempts against real-world targets. While no specific threat actor has been publicly attributed to these activities, security researchers have observed the race condition leveraged to gain root access or to disrupt service availability. The observed abuse typically follows initial compromise through a local account, after which the attacker seeks to elevate privileges. This pattern matches the behaviour expected from the underlying vulnerability.

Defenders should begin by checking the installed libuser version on each Linux host and comparing it to the patched release cited in the Red Hat advisory. If a vulnerable version is present, the update must be deployed promptly, preferably through the normal change management process to avoid unintended disruption. After applying the patch, administrators should examine the /etc/passwd file for any unfamiliar entries and verify that file permissions have not been altered. Additionally, reviewing authentication logs for unexpected su or sudo attempts can help detect any post-exploitation activity.

In the longer term, organisations are encouraged to incorporate KEV identifiers such as CVE-2015-3246 into their vulnerability scanning tools and to treat them with the same urgency as other actively exploited flaws. Maintaining an up-to-date inventory of critical files, enabling file integrity monitoring on /etc/passwd and related configuration files, and restricting interactive local accounts to only those that are required can reduce the attack surface.

Regularly reviewing CISA's KEV catalogue and subscribing to vendor security advisories ensures that similar race condition flaws are not overlooked in future patch cycles.

Intelligence briefing updated Aug 27, 2026

CVE-2015-3246 5.1 KEV
Root sourceaccess.redhat.com
Timeline Coverage

Swipe to explore timeline