CVE-2015-3246
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
5.1
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS — probability of exploitation (30 days)
8.8%
94.9th percentile
CISA KEV
Listed
Added 2026-08-26 · patch by 2026-09-09
Weakness / dates
CWE-367
Published 2015-08-11 · modified 2026-08-27
CVSS breakdown
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | L | Local |
| Attack Complexity | H | High |
| Privileges Required | N | None |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | N | None |
| Integrity | N | None |
| Availability | H | High |
Timeline
- 2015-08-11 — Published (NVD)
- 2026-08-26 — Added to CISA KEV (actively exploited)
- 2026-09-09 — CISA patch-by deadline
- 2026-08-27 — Last modified (NVD)
Description
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Affected
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html
- http://rhn.redhat.com/errata/RHSA-2015-1482.html
- http://rhn.redhat.com/errata/RHSA-2015-1483.html
- http://www.securityfocus.com/bid/76022
- http://www.securitytracker.com/id/1033040
- https://access.redhat.com/articles/1537873
- https://www.exploit-db.com/exploits/44633/
- exploit https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.html
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.html
- http://rhn.redhat.com/errata/RHSA-2015-1482.html
- http://rhn.redhat.com/errata/RHSA-2015-1483.html
- http://www.securityfocus.com/bid/76022
- http://www.securitytracker.com/id/1033040
- https://access.redhat.com/articles/1537873
- https://www.exploit-db.com/exploits/44633/
- exploit https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txt
- https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3246