CVE-2015-3246_Red Hat Libuser Race Condition Vulnerability

Release Date: 26th August 2026

Impact : HIGH

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2015-3246 is a flaw in the way the libuser library handles the /etc/passwd file. The library modifies the file directly, so an authenticated local user who causes an error during that modification can leave the file in an inconsistent state, resulting in denial of service. Red Hat rated the issue as having Important security impact.

The vulnerability is significant principally because it can be chained. Combined with a related flaw, CVE-2015-3245, in which the userhelper program fails to filter newline characters supplied through its chfn interface, a local user can corrupt /etc/passwd in a controlled manner and escalate privileges to the root user. The two issues were discovered together by Qualys during an internal code audit and disclosed on 23 July 2015.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2015-3246
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://access.redhat.com/articles/1537873
  4. https://nvd.nist.gov/vuln/detail/CVE-2015-3246
  5. https://www.cve.org/CVERecord?id=CVE-2015-3245