Posted by Simon McVittie on Sep 26 Was this library advertised as being safe for use in setuid, setgid or otherwise privileged processes? Looking at its description in my package manager ("provides developers of file-sharing networks, file managers, and WWW-indexing bots with a universal library to obtain meta-data about files") I don't immediately see why it would be appropriate for a setuid program to use this. I think it's going to scale incredibly...
Re: CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/959
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.




