Re: CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
Simon McVittie questions whether libextractor CVE-2026-100310 is a realistic setuid privilege escalation.
On oss-security, Simon McVittie replied about CVE-2026-100310, a claimed privilege escalation in GNU libextractor before 1.16 via the LIBEXTRACTOR_PREFIX environment variable. He asked whether the library was ever advertised as safe for setuid, setgid, or other privileged processes. Package descriptions present it as a metadata library for file-sharing networks, file managers, and web-indexing bots. He argues those are not typical setuid use cases, limiting practical impact.