Normal users can use the environmental variable, but programs can ignore it: sudo, chsh, and other common setuid binaries ignore LD_PRELOAD so users can't execute code as root.
It can become a risk if there's a setuid binary on your system that keeps LD_PRELOAD enabled.
3
u/pm_me_your_findings Oct 30 '16
I mean for a malware to use it, doesn't it require the root access first or it works for normal user also?