CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
Other sources
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Hat libuser (usermode package userhelper program)to a version that resolves this vulnerability.Fixed in 0.56.13-8 - Upgrade
Upgrade
Red Hat libuser (usermode package userhelper program)to a version that resolves this vulnerability.Fixed in 0.60-7 - Configuration
If you cannot apply the vendor mitigation/fix, discontinue use of the product because the vulnerable libuser (before 0.56.13-8 and before 0.60-7) directly modifies /etc/passwd and allows local users to corrupt it (DoS/privilege escalation).
userhelper (usermode package) using Red Hat libuser /etc/passwd modification behavior = Avoid direct modification of /etc/passwd - Compensating control
Evaluate each asset’s internet exposure and ensure adherence to CISA BOD 26-04 patching guidelines, prioritizing security updates based on risk.
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3246?
CVE-2015-3246 is classified as a moderate severity vulnerability due to its ability to cause a denial of service by corrupting the /etc/passwd file.
How do I fix CVE-2015-3246?
To fix CVE-2015-3246, you should upgrade to the patched versions of libuser, specifically versions 0.56.13-8 or 0.60-7 and later.
Who is affected by CVE-2015-3246?
CVE-2015-3246 affects users of the libuser library versions prior to 0.56.13-8 and specific versions of 0.60, including 0.60-1 through 0.60-6.
What are the consequences of CVE-2015-3246?
The consequences of CVE-2015-3246 include potential denial of service due to an inconsistent state of the /etc/passwd file after a modification error.
Which software components are vulnerable to CVE-2015-3246?
The vulnerable software components include the userhelper program within the usermode package that utilizes the libuser library prior to the fixed versions.