CVE-2019-19520: OpenBSD

High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.

xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.

Affected products

Published 2019-12-05. Last modified 2026-06-17.