OpenBSD 6.6 xlock contains a dynamic-library loading flaw in Mesa's loader implementation. A local user can supply the LIBGL_DRIVERS_PATH environment variable, causing mishandling of dlopen and enabling elevation to the privileges of the auth group.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a local privilege escalation exploit for OpenBSD systems, targeting CVE-2019-19520 and CVE-2019-19522. The exploit is structured in three files: a README.md with detailed background and exploitation steps, a C proof-of-concept (poc.c) that is compiled into a shared object to be loaded by the vulnerable xlock binary, and a shell script (x.sh) that automates the process of creating a malicious S/Key entry for the root user. The attack proceeds in two stages: first, the attacker uses the C payload to gain 'auth' group privileges via xlock; second, the attacker leverages these privileges to add authentication keys for root in S/Key or YubiKey, ultimately allowing root access. The exploit requires local access and specific OpenBSD configurations, and demonstrates a clear path from unprivileged user to root. The repository contains no detection scripts or fake code, and the exploit is operational, providing a working privilege escalation chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.