CVE-2026-102010

Published: September 29, 2026Last modified: October 10, 2026

Description

A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.

Severity score breakdown

ParameterValue
Base score7
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgccFixed (12.2.1_git20220924-r15)
25 LTSgccFixed (14.3.0-r6)
StreamgccFixed (15.2.0-r11)
Hardened Containers23 LTSgccFixed (12.2.1_git20220924-r15)
25 LTSgccFixed (14.3.0-r6)
StreamgccFixed (15.2.0-r11)

References

ON THIS PAGE