CVE-2026-102010
Published: September 29, 2026Last modified: October 10, 2026
Description
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 7 |
| Attack Vector | NETWORK |
| Attack complexity | HIGH |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | LOW |
| Integrity impact | LOW |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | gcc | Fixed (12.2.1_git20220924-r15) |
| 25 LTS | gcc | Fixed (14.3.0-r6) | |
| Stream | gcc | Fixed (15.2.0-r11) | |
| Hardened Containers | 23 LTS | gcc | Fixed (12.2.1_git20220924-r15) |
| 25 LTS | gcc | Fixed (14.3.0-r6) | |
| Stream | gcc | Fixed (15.2.0-r11) |