{"id":"CVE-2026-102010","title":"A flaw was found in GCC","summary":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","vendor":"Red Hat","product":"gcc","affected":["gcc (all versions)","gcc-toolset-15-gcc (all versions)","gcc-toolset-16 (all versions)","gcc-toolset-16-gcc (all versions)","mingw-gcc (all versions)","compat-gcc-295 (all versions)","compat-gcc-296 (all versions)","compat-gcc-32 (all versions)","compat-gcc-34 (all versions)","gcc (all versions)","compat-gcc-32 (all versions)","compat-gcc-34 (all versions)","compat-gcc-44 (all versions)","gcc (all versions)","gcc (all versions)","gcc-toolset-14-gcc (all versions)","gcc-toolset-15-gcc (all versions)","mingw-gcc (all versions)","rteval-loads (all versions)","gcc (all versions)","gcc-toolset-14-gcc (all versions)","gcc-toolset-15-gcc (all versions)","gcc-toolset-16 (all versions)","gcc-toolset-16-gcc (all versions)","mingw-gcc (all versions)","gcc (all versions)","gcc13 (all versions)","openshift/ose-rhel-coreos-8 (all versions)","openshift/ose-rhel-coreos-9 (all versions)"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T19:16:48.830","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102010","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-102010","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2478395","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-28T19:19:07.733Z","slug":"CVE-2026-102010","body":"## Overview\n\nA flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}