EXPOSURES › CVE-2015-3246
CVE-2015-3246
HIGH ⌖ ON CISA KEV · EXPLOITEDA race condition in Red Hat's libuser allowed authenticated local users to corrupt /etc/passwd, causing denial of service or privilege escalation.
This vulnerability was actively exploited in the wild (KEV) and could be used for privilege escalation or denial of service. DIB organizations must ensure all Red Hat packages are patched to prevent attackers from escalating privileges or disrupting services. The failure highlights the risk of unpatched race conditions in core system utilities.
Shame score — The vulnerability was actively exploited in the wild and allowed privilege escalation, indicating a significant avoidable risk that was not mitigated by timely patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
| PRODUCT | STATUS |
|---|---|
| Red Hat OpenShift Service on AWS (ROSA) Red Hat |
In Process |