Posted by Haitam Lazaar on Sep 25 Hello oss-security, An untrusted search path vulnerability leading to Local Privilege Escalation (LPE) was identified in GNU libextractor for versions prior to 1.16. The vulnerability has been assigned CVE-2026-100310. Description: GNU libextractor before 1.16 uses getenv("LIBEXTRACTOR_PREFIX") in `src/main/extractor_plugpath.c` (`get_installation_paths()`) to determine plugin search paths without checking whether the calling process...
CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/957
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.



