← Terug naar overzicht

CVE-2015-3246 is a race condition vulnerability in Red Hat's libuser library. It allows authenticated local users to corrupt the /etc/passwd file, potentially leading to a denial of service or privilege escalation. The vulnerability affects an open-source component that may be used across multiple products. It has been flagged under CISA's BOD 26-04 directive, which prioritizes security updates based on risk. Forensic triage requirements are also associated with this vulnerability per BOD 26-04 implementation guidance. The vulnerability is rated High severity and has been catalogued in the NVD.

Affected products

  • Red Hat Enterprise Linux
  • Red Hat libuser

Related CVE's

  • CVE-2015-3246

Categories

  • Identity & Access
  • Operating Systems