Description
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 25 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program. | |
| Title | GNU libextractor before 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX | |
| First Time appeared |
Gnu
Gnu libextractor |
|
| Weaknesses | CWE-426 | |
| CPEs | cpe:2.3:a:gnu:libextractor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnu
Gnu libextractor |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-25T19:38:28.517Z
Reserved: 2026-09-25T19:01:58.216Z
Link: CVE-2026-100310
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-426
Untrusted Search Path