haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-1003107.3high[patched]

Local Privilege Escalation via LIBEXTRACTOR_PREFIX Untrusted Search Path

TARGET ECOSYSTEM / VENDORGNU Project
AFFECTED PRODUCTlibextractor (< 1.16)
CWE CLASSIFICATIONCWE-426: Untrusted Search Path
PUBLISHED DATE2026-09-25
ADVISORY / CNARepository / PoC ↗

Summary

GNU libextractor loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. Because it uses getenv() instead of secure_getenv(), this environment variable is not stripped when a process runs with elevated privileges.

Impact & Exploitation

A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious shared object (.so) plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program linking against libextractor.

  • Primary Impact: Local Privilege Escalation (LPE) to root.
  • CNA: VulnCheck
  • Fixed In: GNU libextractor v1.16

Research Repository

A dedicated demonstration repository and standalone PoC are hosted in Haitam-lazaar/libextractor-privesc.