LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 26, 2026
Elevated⚠ Actively exploited (CISA KEV)
Elevated
Severity
Active
CISA KEV
No
Ransomware use
Sep 9, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-3246 to its Known Exploited Vulnerabilities catalog on Aug 26, 2026, with a federal patch deadline of Sep 9, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

CVE-2015-3246 is a race condition vulnerability in Red Hat libuser. Authenticated local users can abuse it to corrupt the /etc/passwd file, leading to denial of service or privilege escalation. It matters because /etc/passwd is central to account and authentication handling on many Linux systems; local compromise of that file can disrupt logins or elevate an already-present attacker’s control. Confirm exact product scope and fixes against the vendor advisory.

This guidance is for IT and security teams inventorying Red Hat-related hosts and applying vendor-directed mitigations in line with risk-based patching practices.

How it works

Public detail describes this as a race condition in Red Hat libuser. In general terms, a race condition occurs when software performs related checks and updates in a way that another process can interleave and change shared state before the first operation finishes. Here, an authenticated local user can contend with libuser operations that touch account data so that /etc/passwd is left in a corrupted state.

Corruption of /etc/passwd can break normal account resolution (denial of service) or create conditions that support privilege escalation for that local user. The weakness is local and requires authentication; it is not described as a remote unauthenticated flaw. Do not assume specific race windows, APIs, or exploit steps beyond this class of behavior—verify mechanics and any related components only in the vendor advisory.

Am I affected? How to find it in your systems

Libuser is a library and related tooling used on some Red Hat and Red Hat-derived Linux systems for user and group account management. It typically appears on servers and workstations where local account administration utilities depend on it, not as a standalone internet-facing service.

How to remediate

Patch first: apply the vendor update for Red Hat libuser as named in the official advisory, and verify installation across all affected image baselines and live hosts. Follow Red Hat’s instructions and your change process; confirm remediation status against the advisory rather than assuming a generic package bump is sufficient.

If you can't patch immediately

Reduce risk until the vendor fix is deployed. Compensating controls for this local race-condition class focus on shrinking who can authenticate locally, protecting the passwd database, and detecting corruption early.

If your data may have been exposed

Actively exploited vulnerabilities can lead to system compromise and follow-on data exposure, especially when privilege escalation succeeds on multi-user hosts. Known ransomware use is not documented for this CVE in the provided facts; still treat confirmed local escalation as an incident. Preserve volatile evidence, review account databases and auth logs, rotate credentials for affected systems, and complete forensics triage as required by your policies and applicable CISA guidance. You can run a free exposure scan of your email to check known breach data for personal addresses tied to your organization.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRed Hat · Libuser
Added to CISA KEVAug 26, 2026
Federal patch deadlineSep 9, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities