CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability

High severity, CVSS 7.4. Actively exploited: in CISA KEV since 2026-08-26. EPSS: 8.4% chance of exploitation in the next 30 days.

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

Affected products

  • Libuser Project Libuser: before 0.56.13-8 (fixed in 0.56.13-8); from 0.60, before 0.60-7 (fixed in 0.60-7)
  • Opensuse Opensuse: version 13.2 only
  • Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only

Published 2015-08-11. Last modified 2026-10-02.