← Back to CVE Registry
CVE-2026-1003107.3high[patched]
Local Privilege Escalation via LIBEXTRACTOR_PREFIX Untrusted Search Path
TARGET ECOSYSTEM / VENDORGNU Project
AFFECTED PRODUCTlibextractor (< 1.16)
CWE CLASSIFICATIONCWE-426: Untrusted Search Path
PUBLISHED DATE2026-09-25
ADVISORY / CNARepository / PoC ↗
Summary
GNU libextractor loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. Because it uses getenv() instead of secure_getenv(), this environment variable is not stripped when a process runs with elevated privileges.
Impact & Exploitation
A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious shared object (.so) plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program linking against libextractor.
- Primary Impact: Local Privilege Escalation (LPE) to
root. - CNA: VulnCheck
- Fixed In: GNU libextractor v1.16
Research Repository
A dedicated demonstration repository and standalone PoC are hosted in Haitam-lazaar/libextractor-privesc.