CISA KEV backfill: two 2015-era Red Hat local privilege-escalation bugs (CVE-2015-3246, CVE-2015-5287)
CISA's August 26 KEV batch included two decade-old Red Hat bugs this pipeline's window missed at the time: a libuser race condition that lets an authenticated local user corrupt /etc/passwd (CVE-2015-3246), and a symlink attack in the Automatic Bug Reporting Tool that escalates local privileges via a predictable temp file (CVE-2015-5287). Both are local-only, EoL-adjacent, and only matter if you're still running RHEL-era hosts with libuser or ABRT installed — but a KEV listing means CISA has evidence of active exploitation somewhere, however old. If you have legacy Red Hat systems still in service, confirm libuser and abrt are patched or removed; there's no supply-chain angle here, just two old holes getting caught by the backfill window.