{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/libextractor--1.16/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gnu:libextractor:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-100310"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libextractor (\u003c 1.16)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","linux","vulnerability"],"_cs_type":"advisory","_cs_vendors":["GNU"],"content_html":"\u003cp\u003eGNU libextractor before version 1.16 contains a vulnerability where the library fails to properly validate the LIBEXTRACTOR_PREFIX environment variable when searching for plugins. Because this variable influences the library's plugin loading path, a local attacker can set it to a directory they control. If a setuid or setgid binary utilizes libextractor, the library will load and execute malicious plugins located in the attacker-supplied directory with the privileges of the binary. This vulnerability allows an attacker to achieve privilege escalation on the host system. This is particularly critical in environments where setuid/setgid binaries are commonly used or where libextractor is embedded in privileged services.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables a local attacker to execute arbitrary code with elevated privileges. This could lead to a full system compromise, data theft, or persistence on the affected host. The scope is limited to systems where libextractor is utilized by setuid or setgid programs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade libextractor to version 1.16 or later immediately to address the insecure environment variable handling.\u003c/li\u003e\n\u003cli\u003eAudit existing setuid and setgid binaries on Linux systems to determine if they are linked against the affected libextractor library.\u003c/li\u003e\n\u003cli\u003eImplement environment variable sanitization policies for high-privilege service accounts to prevent the injection of arbitrary paths into library search variables.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T20:55:35Z","date_published":"2026-09-25T20:55:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-libextractor-rce/","summary":"GNU libextractor versions prior to 1.16 are vulnerable to arbitrary code execution due to the insecure handling of the LIBEXTRACTOR_PREFIX environment variable, which can be leveraged by local attackers for privilege escalation.","title":"Arbitrary Code Execution in GNU libextractor via Environment Variable Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-libextractor-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Libextractor (\u003c 1.16)","version":"https://jsonfeed.org/version/1.1"}