CVE-2026-100310: Untrusted Search Path in GNU libextractor
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.
AI Analysis
Technical Summary
CVE-2026-100310 describes an untrusted search path vulnerability in GNU libextractor prior to version 1.16. The vulnerability arises because libextractor loads plugins from a path defined by the LIBEXTRACTOR_PREFIX environment variable without verifying the trustworthiness of that path. This allows a local attacker with limited privileges to specify a directory containing a malicious plugin. When a setuid or setgid program loads this plugin, the malicious code executes with elevated privileges, potentially compromising the system.
Potential Impact
A local attacker can gain elevated privileges by exploiting this vulnerability, leading to arbitrary code execution with the privileges of the setuid or setgid program that loads the malicious plugin. This can result in unauthorized system access or control.
Mitigation Recommendations
A fix is available in GNU libextractor version 1.16 and later. Users should upgrade to version 1.16 or newer to remediate this vulnerability. Until then, avoid running setuid or setgid programs that load libextractor plugins with untrusted LIBEXTRACTOR_PREFIX environment variables.
CVE-2026-100310: Untrusted Search Path in GNU libextractor
Description
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.
CVSS v4.0
Score 7.3high
Affected software
GNU
libextractor
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100310 describes an untrusted search path vulnerability in GNU libextractor prior to version 1.16. The vulnerability arises because libextractor loads plugins from a path defined by the LIBEXTRACTOR_PREFIX environment variable without verifying the trustworthiness of that path. This allows a local attacker with limited privileges to specify a directory containing a malicious plugin. When a setuid or setgid program loads this plugin, the malicious code executes with elevated privileges, potentially compromising the system.
Potential Impact
A local attacker can gain elevated privileges by exploiting this vulnerability, leading to arbitrary code execution with the privileges of the setuid or setgid program that loads the malicious plugin. This can result in unauthorized system access or control.
Mitigation Recommendations
A fix is available in GNU libextractor version 1.16 and later. Users should upgrade to version 1.16 or newer to remediate this vulnerability. Until then, avoid running setuid or setgid programs that load libextractor plugins with untrusted LIBEXTRACTOR_PREFIX environment variables.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-25T19:01:58.216Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab6d01ff7a7c54106357d88
Added to database: 09/25/2026, 19:48:47 UTC
Last enriched: 09/25/2026, 20:02:43 UTC
Last updated: 09/26/2026, 04:50:59 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.