{"id":"DEBIAN-CVE-2026-102010","details":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.","modified":"2026-10-01T08:47:30.739806880Z","published":"2026-09-28T19:16:48.830Z","upstream":["CVE-2026-102010"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-102010"}],"affected":[{"package":{"name":"gcc-12","ecosystem":"Debian:12","purl":"pkg:deb/debian/gcc-12?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["12.2.0-14","12.2.0-14+deb12u1","12.2.0-14+hurd.1","12.2.0-14+loong64","12.2.0-14+loong64.1","12.2.0-15","12.2.0-16","12.2.0-17","12.2.0-18","12.3.0-1","12.3.0-10","12.3.0-11","12.3.0-12","12.3.0-13","12.3.0-14","12.3.0-15","12.3.0-16","12.3.0-17","12.3.0-2","12.3.0-3","12.3.0-3~exp1","12.3.0-4","12.3.0-5","12.3.0-6","12.3.0-7","12.3.0-8","12.3.0-9","12.4.0-1","12.4.0-2","12.4.0-3","12.4.0-4","12.4.0-5","12.4.0-6","12.4.0-7","12.4.0-8","12.4.0-8~alpha","12.5.0-1","12.5.0-2","12.5.0-3","12.5.0-4","12.5.0-5","12.5.0-6","12.5.0-7","12.5.0-8","12.5.0-9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"}},{"package":{"name":"gcc-12","ecosystem":"Debian:13","purl":"pkg:deb/debian/gcc-12?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["12.4.0-5","12.4.0-6","12.4.0-7","12.4.0-8","12.4.0-8~alpha","12.5.0-1","12.5.0-2","12.5.0-3","12.5.0-4","12.5.0-5","12.5.0-6","12.5.0-7","12.5.0-8","12.5.0-9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"}},{"package":{"name":"gcc-12","ecosystem":"Debian:14","purl":"pkg:deb/debian/gcc-12?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["12.4.0-5","12.4.0-6","12.4.0-7","12.4.0-8","12.4.0-8~alpha","12.5.0-1","12.5.0-2","12.5.0-3","12.5.0-4","12.5.0-5","12.5.0-6","12.5.0-7","12.5.0-8","12.5.0-9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"}},{"package":{"name":"gcc-14","ecosystem":"Debian:13","purl":"pkg:deb/debian/gcc-14?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["14.2.0-19","14.2.0-20","14.2.0-21","14.2.0-22","14.2.0-23","14.2.0-24","14.2.0-25","14.3.0-1","14.3.0-10","14.3.0-11","14.3.0-12","14.3.0-13","14.3.0-14","14.3.0-15","14.3.0-16","14.3.0-2","14.3.0-3","14.3.0-4","14.3.0-5","14.3.0-6","14.3.0-7","14.3.0-8","14.3.0-9","14.4.0-1","14.4.0-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"}},{"package":{"name":"gcc-14","ecosystem":"Debian:14","purl":"pkg:deb/debian/gcc-14?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["14.2.0-19","14.2.0-20","14.2.0-21","14.2.0-22","14.2.0-23","14.2.0-24","14.2.0-25","14.3.0-1","14.3.0-10","14.3.0-11","14.3.0-12","14.3.0-13","14.3.0-14","14.3.0-15","14.3.0-16","14.3.0-2","14.3.0-3","14.3.0-4","14.3.0-5","14.3.0-6","14.3.0-7","14.3.0-8","14.3.0-9","14.4.0-1","14.4.0-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"}},{"package":{"name":"gcc-15","ecosystem":"Debian:14","purl":"pkg:deb/debian/gcc-15?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["15-20241128-1","15-20241214-1","15-20241220-1","15-20241231-1","15-20250112-1","15-20250114-1","15-20250130-1","15-20250130-2","15-20250203-1","15-20250208-1","15-20250213-1","15-20250220-1","15-20250315-1","15-20250319-1","15-20250329-1","15-20250406-1","15-20250423-1","15.1.0-1","15.1.0-10","15.1.0-11","15.1.0-2","15.1.0-3","15.1.0-4","15.1.0-5","15.1.0-6","15.1.0-7","15.1.0-8","15.1.0-8+sh4","15.1.0-8+sh4.1","15.1.0-9","15.2.0-1","15.2.0-10","15.2.0-11","15.2.0-12","15.2.0-13","15.2.0-14","15.2.0-15","15.2.0-16","15.2.0-17","15.2.0-2","15.2.0-3","15.2.0-4","15.2.0-5","15.2.0-6","15.2.0-7","15.2.0-8","15.2.0-9","15.3.0-1","15.3.0-2","15.3.0-3","15.3.0-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"}},{"package":{"name":"gcc-16","ecosystem":"Debian:14","purl":"pkg:deb/debian/gcc-16?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["16-20251130-1","16-20251202-1","16-20251210-1","16-20251214-1","16-20260119-1","16-20260203-1","16-20260203-2","16-20260207-1","16-20260207-2","16-20260208-1","16-20260217-1","16-20260226-1","16-20260307-1","16-20260308-1","16-20260308-1+sh4","16-20260315-1","16-20260322-1","16-20260423-1","16-20260425-1","16.1.0-1","16.1.0-2","16.1.0-3","16.2.0-1","16.2.0-2","16.2.0-3"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}