CVE Tools

CVE-2015-3246

Exploited in the wild. In CISA KEV since 2026‑08‑26. A vendor fix is available.

Published Updated Sources: CVE.org, NVD

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether libuser is installed and what version you run on your systems.
  2. If your libuser version is earlier than 0.56.13-8 (or in affected branches), plan an update immediately.
  3. Apply the vendor fix by upgrading libuser to a version that is fixed (libuser fixed in 0.56.13-8).
  4. After updating, re-verify account management works normally and watch for unusual failures in user/account changes.

What it is

From the CVE record

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

In plain language

Written by AI from the record

This is a Linux system bug in libuser that lets any local user crash or break account-management by interrupting an update to the user list; if your server has local user access, you should act and update.

CVE-2015-3246 is a local denial-of-service in libuser’s userhelper (as used in usermode) where an error during the user account file update can leave /etc/passwd in an inconsistent state, breaking account management; it is listed in CISA KEV and has confirmed exploitation in the wild.

If you're affected

  • System account management broken
  • Login/account disruptions
  • Potential denial of service
  • Requires emergency recovery effort

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS95th
Public exploit
CISA KEV
CISA KEV

Listed as exploited in the wild since 2026-08-26.

US federal agencies must remediate by 2026-09-09.

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Public exploits

1 source with a proof of concept or module.

Exploit links, PoCs and Metasploit modules after sign-in
EPSS

8.8% chance of exploitation activity in the next 30 days, which ranks it in the 95th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

A public exploit existed 173 days before the patch.

  1. Analysis publishedCISA's Newest KEV Batch Has an 11-Year-Old Bug in It — But Not All Six Are the Same Story
  2. Patch availableworkaround available, record updated
  3. Added to CISA KEVpatch available, workaround available, record updated, record updated
  4. OpenVAS check added
  5. EPSS band changemoderate → low
  6. Record updated

Affected products

And 1 more affected product. See all after sign-in

Technical detail

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Scored 5.1 by NVD.

How it is reached

  • Attack Vector LocalRequires local access to the vulnerable system (e.g. local login, malicious file)
  • Attack Complexity HighRequires specific conditions like a race condition or non-default configuration
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality NoneNo confidentiality impact
  • Integrity NoneNo integrity impact
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Enterprise Linux, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store