Bug 2541609 (CVE-2026-100310)

Summary: CVE-2026-100310 libextractor: libextractor: Privilege escalation via LIBEXTRACTOR_PREFIX environment variable
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in libextractor. When executed by privileged applications, such as those running with elevated set user ID (setuid) permissions, the library loads plugins from an untrusted search path defined by the LIBEXTRACTOR_PREFIX environment variable without verifying caller privileges. A local attacker can exploit this issue by pointing the variable to a directory containing a crafted plugin, leading to arbitrary code execution with elevated privileges.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-25 19:51:26 UTC
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.