given a welcome binary that don't have exec flag on it
and a wrapper binary that has setuid (user that can read the flag.txt file )
The idea was to execute welcome binary using the linker "/lib/ld*.so" as ELF interpreter
so running the wrapper binary then just
/lib64/ld-linux-x86-64.so.2 ./welcome
will print the flag