Posted by Haitam Lazaar on Sep 25 Hello oss-security, An untrusted search path vulnerability leading to Local Privilege Escalation (LPE) was identified in GNU libextractor for versions prior to 1.16. The vulnerability has been assigned CVE-2026-100310. Description: GNU libextractor before 1.16 uses getenv("LIBEXTRACTOR_PREFIX") in `src/main/extractor_plugpath.c` (`get_installation_paths()`) to determine plugin search paths without checking whether the calling process...

Read the full article at oss-security →