CVE-2015-3246
published 2015-08-11CVE-2015-3246: libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local…
PriorityP274medium5.1CVSS 3.1
AVLACHPRNUINSUCNINAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-09-09
Exploited in the wild
EPSS
8.80%
94.9th percentile
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libuser | < libuser 1:0.62~dfsg-0.1 (bookworm) | libuser 1:0.62~dfsg-0.1 (bookworm) |
| libuser | libuser | >= 0 < 1:0.62~dfsg-0.1 | 1:0.62~dfsg-0.1 |
| libuser | libuser | >= 0 < 1:0.62~dfsg-0.1 | 1:0.62~dfsg-0.1 |
| libuser | libuser | >= 0 < 1:0.62~dfsg-0.1 | 1:0.62~dfsg-0.1 |
| libuser | libuser | >= 0 < 1:0.62~dfsg-0.1 | 1:0.62~dfsg-0.1 |
| libuser_project | libuser | < 0.56.13-8 | 0.56.13-8 |
| libuser_project | libuser | >= 0.60 < 0.60-7 | 0.60-7 |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv2.1LOW
vulncheck2.1LOW
cisa5.1MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Red Hat Libuser Race Condition Vulnerability
cisa·2026-08-26·CVSS 5.1
CVE-2015-3246 [MEDIUM] Red Hat Libuser Race Condition Vulnerability
Vulnerability: Red Hat Libuser Race Condition Vulnerability
Affected: Red Hat Libuser
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes: This vulnerability
Red Hat
libuser: Security flaw in handling /etc/passwd file
vendor_redhat·2015-07-23·CVSS 2.1
CVE-2015-3246 [LOW] libuser: Security flaw in handling /etc/passwd file
libuser: Security flaw in handling /etc/passwd file
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
A flaw was found in the way the libuser library handled the /etc/passwd file. A local attacker could use an application compiled against libuser (for example, userhelper) to manipulate the /etc/passwd file, which could result in a denial of service or possibly allow the attacker to escalate their privileges to root.
Statement: This issue affects the versions of libuser as shipped with Red Hat Enterprise Li
Debian
CVE-2015-3246: libuser - libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper progr...
vendor_debian·2015·CVSS 2.1
CVE-2015-3246 [LOW] CVE-2015-3246: libuser - libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper progr...
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Scope: local
bookworm: resolved (fixed in 1:0.62~dfsg-0.1)
bullseye: resolved (fixed in 1:0.62~dfsg-0.1)
forky: resolved (fixed in 1:0.62~dfsg-0.1)
sid: resolved (fixed in 1:0.62~dfsg-0.1)
trixie: resolved (fixed in 1:0.62~dfsg-0.1)
VulDB
libuser up to 0.56.13-7/0.60-6 userhelper /etc/passwd access control (RHSA-2015:1483 / EDB-44633)
vuldb·2026-08-26·CVSS 5.1
CVE-2015-3246 [MEDIUM] libuser up to 0.56.13-7/0.60-6 userhelper /etc/passwd access control (RHSA-2015:1483 / EDB-44633)
A vulnerability, which was classified as problematic, has been found in libuser up to 0.56.13-7/0.60-6. This vulnerability affects unknown code of the file /etc/passwd of the component userhelper. Performing a manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2015-3246. The attack must be initiated from a local position. Furthermore, there is an exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-f52h-j689-x786: libuser before 0
ghsa_unreviewed·2022-05-14·CVSS 2.1
CVE-2015-3246 [LOW] GHSA-f52h-j689-x786: libuser before 0
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
OSV
CVE-2015-3246: libuser before 0
osv·2015-08-11·CVSS 2.1
CVE-2015-3246 [LOW] CVE-2015-3246: libuser before 0
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
VulnCheck
libuser 'passwd' File Handling Vulnerability
vulncheck·2015·CVSS 2.1
CVE-2015-3246 [LOW] libuser 'passwd' File Handling Vulnerability
libuser 'passwd' File Handling Vulnerability
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Affected: Red Hat libuser
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
No detection rules found.
Exploit-DB
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
exploitdb·2018-05-16
CVE-2015-3246 Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Libuser roothelper Privilege Escalation',
'Description' => %q{
This module attempts to gain root privileges on Red Hat based Linux
systems, including RHEL, Fedora and CentOS, by exploiting a newline
injection vulnerability in libuser and userhelper versions prior to
0.56.13-8 and version 0.60 before 0.60-7.
This module makes use of the roothelper.c exploit from Qualys to
insert a new user with UID=0 in /etc/passwd.
Note, the password for the current user is required by userhelper.
Note, on some systems, such as Fedora 11, the user entry for the
current user i
Exploit-DB
Libuser Library - Multiple Vulnerabilities
exploitdb·2015-07-27·CVSS 2.1
CVE-2015-3246 [LOW] Libuser Library - Multiple Vulnerabilities
Libuser Library - Multiple Vulnerabilities
---
Qualys Security Advisory
CVE-2015-3245 userhelper chfn() newline filtering
CVE-2015-3246 libuser passwd file handling
--[ Summary ]-----------------------------------------------------------------
The libuser library implements a standardized interface for manipulating
and administering user and group accounts, and is installed by default
on Linux distributions derived from Red Hat's codebase. During an
internal code audit at Qualys, we discovered multiple libuser-related
vulnerabilities that allow local users to perform denial-of-service and
privilege-escalation attacks. As a proof of concept, we developed an
unusual local root exploit against one of libuser's applications.
----[ Vulnerability #1 (CVE-2015-3245 userhelper chfn() newl
Metasploit
Libuser roothelper Privilege Escalation
metasploit
Libuser roothelper Privilege Escalation
Libuser roothelper Privilege Escalation
This module attempts to gain root privileges on Red Hat based Linux systems, including RHEL, Fedora and CentOS, by exploiting a newline injection vulnerability in libuser and userhelper versions prior to 0.56.13-8 and version 0.60 before 0.60-7. This module makes use of the roothelper.c exploit from Qualys to insert a new user with UID=0 in /etc/passwd. Note, the password for the current user is required by userhelper. Note, on some systems, such as Fedora 11, the user entry for the current user in /etc/passwd will become corrupted and exploitation will fail. This module has been tested successfully on libuser packaged versions 0.56.13-4.el6 on CentOS 6.0 (x86_64); 0.56.13-5.el6 on CentOS 6.5 (x86_64); 0.60-5.el7 on CentOS 7.1-1503 (x86_64); 0.56.16
Recorded Future
August 2026 CVE Landscape
blogs_recorded_future·2026-09-08·CVSS 8.8
CVE-2025-62593 [HIGH] August 2026 CVE Landscape
## August 2026 CVE Landscape
In August 2026, Insikt Group® identified 73 high-impact vulnerabilities that should be prioritized for remediation , 43 of which had a Very Critical Recorded Future Risk Score. This represents a 14% decrease from last month. 31 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 32 were reported in open sources and validated by Insikt Group, seven were sourced through security vendor telemetry, and three were exclusively surfaced through honeypot data.
The 73 vulnerabilities in this blog affected products from 45 vendors, with Microsoft accounting for approximately 11% of the vulnerabilities. The remaining exposure spanned remote monitoring and managemen
Hackernews
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
blogs_hackernews·2026-08-27·CVSS 5.1
CVE-2019-1068 [MEDIUM] CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2019-1068 - A remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
CVE-2026-8452 - An impr
Hackernews
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
blogs_hackernews·2026-08-24
CVE-2022-0995 UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.
The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open directory hosted at "139.180.197[.]150," which was observed communicating with one of the compromised machines.
"The actor leveraged publicly d
Talos
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
blogs_talos·2026-08-20
CVE-2022-0995 UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
## UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos identified UAT-10147 targeting Windows and Linux web servers globally, impacting organizations in government, education, media, technology, and gaming sectors. The actor leveraged publicly disclosed vulnerabilities to gain initial access at scale.
UAT-10147 integrated AI-driven tooling into exploitation, reconnaissance, payload generation, validation, and persistence workflows. Talos observed AI-generated operational playbooks, exploit automation scripts, and troubleshooting logic supporting real-world intrusions.
The actor employed a mixture of open-source offensive frameworks, including Metasploit, ysoserial, PentestGPT, DeepAudit, and multiple privilege escalation exploits to au
Bugzilla
CVE-2015-3245 CVE-2015-3246 libuser: various flaws [fedora-all]
bugzilla·2015-07-23·CVSS 2.1
CVE-2015-3245 [LOW] CVE-2015-3245 CVE-2015-3246 libuser: various flaws [fedora-all]
CVE-2015-3245 CVE-2015-3246 libuser: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2015-3246 libuser: Security flaw in handling /etc/passwd file
bugzilla·2015-06-18·CVSS 2.1
CVE-2015-3246 [LOW] CVE-2015-3246 libuser: Security flaw in handling /etc/passwd file
CVE-2015-3246 libuser: Security flaw in handling /etc/passwd file
A flaw was found in the way libuser handled /etc/passwd file. Even though traditional programs like passwd, chfn, and chsh work on a temporary copy of /etc/passwd and eventually rename() it, libuser modifies /etc/passwd directly. Unfortunately, if anything goes wrong during these modifications, libuser may leave /etc/passwd in an inconsistent state.
This can cause a local denial-of-service. Also when combined with CVE-2015-3245, it could result in privilege escalation to root user.
Acknowledgements:
Red Hat would like to thank Qualys for reporting this issue.
Discussion:
External References:
https://access.redhat.com/articles/1537873
---
This issue has been addressed in the following products:
Red Hat Enterprise L
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1482.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1483.htmlhttp://www.securityfocus.com/bid/76022http://www.securitytracker.com/id/1033040https://access.redhat.com/articles/1537873https://www.exploit-db.com/exploits/44633/https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txthttp://lists.fedoraproject.org/pipermail/package-announce/2015-August/163044.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-July/162947.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1482.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1483.htmlhttp://www.securityfocus.com/bid/76022http://www.securitytracker.com/id/1033040https://access.redhat.com/articles/1537873https://www.exploit-db.com/exploits/44633/https://www.qualys.com/2015/07/23/cve-2015-3245-cve-2015-3246/cve-2015-3245-cve-2015-3246.txthttps://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-3246
2015-08-11
Published
2026-08-26
Added to CISA KEV
Exploited in the wild