PT-2026-99099 · Gnu · Libextractor

·

CVE-2026-100310

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU libextractor versions prior to 1.16
Description The software loads plugins from an untrusted search path defined by the LIBEXTRACTOR PREFIX environment variable without performing proper privilege checks. A local attacker can manipulate the LIBEXTRACTOR PREFIX variable to point to a directory containing a malicious plugin. When a setuid or setgid program loads this plugin, it allows the execution of arbitrary code with elevated privileges.
Recommendations Update GNU libextractor to version 1.16 or later.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100310

Affected Products

Libextractor