Exploited Known exploited (KEV) CVE-2015-3246

A 2015 CVE added to KEV in 2026 - an old weakness recorded as exploited now (Red Hat libuser, CVE-2015-3246)

Red Hat Libuser Added to KEV Aug 26, 2026 Federal remediation due 2026-09-09

A race condition vulnerability in Red Hat libuser has been added to CISA's Known Exploited Vulnerabilities catalog. Authenticated local users can corrupt /etc/passwd to cause denial of service or privilege escalation. The CVE number dates from 2015.

Key facts

  • CVE IDCVE-2015-3246
  • Affected (vendor / product)Red Hat Libuser
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-09-09 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • A race condition in Red Hat libuser lets authenticated local users corrupt /etc/passwd, causing denial of service or privilege escalation.
  • The CVE number dates from 2015 while KEV addition came on 26 August 2026, meaning exploitation is confirmed now.
  • Of the 1,687 KEV records this site holds as of 2026-09-02, 724 (43 per cent) have the CVE year equal to the year added.
  • Ninety-one records carry a gap of ten years or more, the longest being 20 years.
  • A race condition exploits the small interval between checking a state and acting on it.
  • Low-level libraries may not appear in an asset inventory, and KEV listing becomes the occasion to take stock.

1A number eleven years old, listed now

KEV is a list of vulnerabilities confirmed as exploited. What this record means, then, is that a weakness found in 2015 is being exploited now. The age of a number does not put the danger in the past.

KEV records held by this site1,687CISA catalog of exploited vulnerabilities
CVE year same as year added72443 per cent of the whole
Ten years or more apart91the longest gap is 20 years

While 43 per cent are added in the year of the CVE, 91 records carry a gap of ten years or more. How long ago something was published and whether it is being targeted now are separate questions.

2What a race condition is

  1. 1CheckThe program confirms the state of a target file
  2. 2A gap opensTime passes between the check and the actual operation
  3. 3It is swappedAnother process replaces the target in that interval
  4. 4It breaks/etc/passwd is corrupted, causing denial of service or privilege escalation

A race condition exploits the small interval between checking and acting. Exploitation requires being authenticated on the target environment, which is enough to serve as a foothold for an attacker already inside to raise privilege.

3Why old weaknesses persist

The longer a system runs, the more components it carries whose updates have stopped. Low-level libraries like libuser often keep running without being consciously noticed and may not appear in an asset inventory at all. Appearing in KEV becomes the occasion to take stock of those unseen old parts. Nine records this site holds as of 2026-09-02 concern Red Hat.

Why it matters

Vulnerability management weighted toward newly published items responds late when an old number appears in KEV. The longer a system has run, the more low-level components it carries whose updates have stopped, and those may not appear in an inventory. Because KEV is ordered by the fact of exploitation rather than year of publication, cutting off by year is dangerous.

FAQ

Why is a 2015 CVE listed now?
KEV lists vulnerabilities confirmed as exploited. Regardless of the age of the number, listing indicates exploitation now.
What is a race condition?
A weakness exploiting the interval between a program checking a target state and acting on it, during which another process replaces the target.
Can it be exploited remotely?
According to CISA it is exploitation by authenticated local users, which can serve as a foothold for an attacker already inside to raise privilege.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#CISA#Red Hat#race condition#privilege escalation#old CVEs
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.