CVE-2015-3246
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Early warning: exploitation observed
- Exploitation observed since Aug 20, 2026
- Not yet in the official CISA catalogue
- First attack observed 4026 days after disclosure
Source: VulnCheck KEV · Aug 20, 2026
CVSS score7.2 / 10
AV:L/AC:L/Au:N/C:C/I:C/A:CWeakness type (CWE)CWE-264
Vendorsredhat
Affected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| redhat | libuser | <= 0.56.13-5 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
