Description
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
In plain language
AI Act nowThis is a Linux system bug in libuser that lets any local user crash or break account-management by interrupting an update to the user list; if your server has local user access, you should act and update.
CVE-2015-3246 is a local denial-of-service in libuser’s userhelper (as used in usermode) where an error during the user account file update can leave /etc/passwd in an inconsistent state, breaking account management; it is listed in CISA KEV and has confirmed exploitation in the wild.
What to do now
- Check whether libuser is installed and what version you run on your systems.
- If your libuser version is earlier than 0.56.13-8 (or in affected branches), plan an update immediately.
- Apply the vendor fix by upgrading libuser to a version that is fixed (libuser fixed in 0.56.13-8).
- After updating, re-verify account management works normally and watch for unusual failures in user/account changes.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)en-us·Help Net Security· Exploited Citrix NetScaler ADC rce
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugsen·The Hacker News· Exploited Citrix NetScaler ADC zero-day
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkiten·The Hacker News· Exploited UAT-10147 malware
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsen·Cisco Talos· Exploited Windows Server UAT-10147
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2015-3246 and every CVE in our database. Create a free account — no credit card required.
Create Free Account