A notice published on September 25, 2026 reports that GNU libextractor versions before 1.16 may allow local privilege escalation through untrusted plugin search paths.
A notice published on September 25, 2026 in the oss-sec feed reports CVE-2026-100310 in GNU libextractor versions before 1.16. According to the available excerpt, the program uses the LIBEXTRACTOR_PREFIX environment variable to determine plugin search paths without the necessary check for untrusted paths; this may allow local privilege escalation. The supplied text is truncated and is an automatic translation.
To assess impact, consult the original post in the oss-sec archive and confirm affected details and versions in official project sources. Check which versions are installed in your organization and follow update guidance; the notice itself does not state a fix beyond identifying version 1.16. If you use AI to summarize or analyze the material, avoid including internal data or identifiers and verify conclusions against original technical sources.