#1150194 gcc-16: CVE-2026-102010

Package:
src:gcc-16
Source:
src:gcc-16
Submitter:
Moritz Mühlenhoff
Date:
2026-10-06 20:43:02 UTC
Severity:
normal
Tags:
#1150194#5
Date:
2026-10-06 20:14:26 UTC
From:
To:
Hi,

The following vulnerability was published for gcc-16.

CVE-2026-102010[0]:
| A flaw was found in GCC. When an application calls the erase_if
| function on a binary heap priority queue in libstdc++, the library
| reallocates storage but fails to update its internal entry pointer.
| An attacker capable of triggering this operation can exploit this
| use-after-free condition, leading to a Denial of Service (DoS) via
| an application crash or potential memory corruption.

https://gcc.gnu.org/bugzilla/show_bug.cgi?id=127656


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102010
https://www.cve.org/CVERecord?id=CVE-2026-102010

Please adjust the affected versions in the BTS as needed.