<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:redhat:libuser:0.60-2:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aredhatlibuser0.60-2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 26 Aug 2026 20:17:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aredhatlibuser0.60-2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-08-libuser-race-condition/</link><pubDate>Wed, 26 Aug 2026 20:17:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-libuser-race-condition/</guid><description>Red Hat Libuser contains a race condition vulnerability allowing authenticated local users to corrupt /etc/passwd, potentially leading to privilege escalation or denial of service.</description><content:encoded><![CDATA[<p>CVE-2015-3246 is a race condition vulnerability within the Red Hat Libuser library, a component used for user and group administration. The vulnerability exists because the library fails to properly handle race conditions when updating sensitive system files, specifically /etc/passwd. An authenticated local user can exploit this weakness to induce file corruption. Depending on the success of the race condition, an attacker may achieve unauthorized privilege escalation or crash services dependent on the integrity of the user database, resulting in a denial of service. Because Libuser is a library used by various system utilities, the impact is highly dependent on the local environment and the specific applications invoking the library functions. This vulnerability is subject to CISA BOD 26-04 requirements for timely remediation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows local authenticated users to gain elevated privileges on the host system or render critical system authentication services unavailable. This poses a significant risk for multi-user Linux environments where non-privileged users have the ability to execute commands and interact with local system utilities that link against the vulnerable library.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply vendor-provided security patches for Libuser immediately to address CVE-2015-3246.</li>
<li>Adhere to CISA BOD 26-04 requirements by identifying and patching all systems utilizing the affected library within the specified remediation window.</li>
<li>Prioritize the remediation of internet-exposed assets that leverage Libuser for user management functions.</li>
<li>Audit host systems for unauthorized modifications to /etc/passwd or /etc/shadow as part of broader integrity monitoring.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>