#1150198 gcc-12: CVE-2026-102010

Package:
src:gcc-12
Source:
src:gcc-12
Submitter:
Moritz Mühlenhoff
Date:
2026-10-09 09:07:04 UTC
Severity:
normal
Tags:
#1150198#5
Date:
2026-10-06 20:15:59 UTC
From:
To:
Hi,

The following vulnerability was published for gcc-12.

CVE-2026-102010[0]:
| A flaw was found in GCC. When an application calls the erase_if
| function on a binary heap priority queue in libstdc++, the library
| reallocates storage but fails to update its internal entry pointer.
| An attacker capable of triggering this operation can exploit this
| use-after-free condition, leading to a Denial of Service (DoS) via
| an application crash or potential memory corruption.

https://gcc.gnu.org/bugzilla/show_bug.cgi?id=127656


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102010
https://www.cve.org/CVERecord?id=CVE-2026-102010

Please adjust the affected versions in the BTS as needed.

#1150198#12
Date:
2026-10-09 09:06:52 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
gcc-12, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1150198@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Matthias Klose <doko@debian.org> (supplier of updated gcc-12 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 09 Oct 2026 10:26:51 +0200
Source: gcc-12
Architecture: source
Version: 12.5.0-11
Distribution: unstable
Urgency: medium
Maintainer: Debian GCC Maintainers <debian-gcc@lists.debian.org>
Changed-By: Matthias Klose <doko@debian.org>
Closes: 1150198
Changes:
 gcc-12 (12.5.0-11) unstable; urgency=medium
 .
   * Fix PR libstdc++/127656: Fix use-after-free in pbds binary heap,
     taken from the gcc-14 branch.  CVE-2026-102010. Closes: #1150198.
Checksums-Sha1:
 4640524bdbe3c304756399fa010b209d13697151 21584 gcc-12_12.5.0-11.dsc
 8ddccf07bc2b7f495039ca7ae87fc20cafa8e304 581632 gcc-12_12.5.0-11.debian.tar.xz
 6940ba9089cf2dc698f01e5e4ceb55a350dfa7e6 8499 gcc-12_12.5.0-11_source.buildinfo
Checksums-Sha256:
 c56252fd8dc319e124545e117f0a213cdc1e1ec64e961d8a941caba882e801d8 21584 gcc-12_12.5.0-11.dsc
 2717a148a43749e8610d9b2186cbcff098c3c91d2864d45572bca292d626357b 581632 gcc-12_12.5.0-11.debian.tar.xz
 c96132c7dcdb46844b4d7babc9c98063c6adfdf0947dfa4995fc191319be3823 8499 gcc-12_12.5.0-11_source.buildinfo
Files:
 e4ad7a6e01b7957d609d87e3fd0ed890 21584 devel optional gcc-12_12.5.0-11.dsc
 e1ccca7a123cf0ea67e67926842480f6 581632 devel optional gcc-12_12.5.0-11.debian.tar.xz
 ad1ada783759f210923d715b94aafa63 8499 devel optional gcc-12_12.5.0-11_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJEBAEBCgAuFiEE1WVxuIqLuvFAv2PWvX6qYHePpvUFAmrIqUQQHGRva29AZGVi
aWFuLm9yZwAKCRC9fqpgd4+m9RDMD/9QFE7fEECpT1DDaBrjOTbSRwOcn5Jwghvw
yEh0qUbh55CrIpx39/1cIe+ftxVw2e2bWdszbkp5K9OXkE3+LX4YYl+U13tlHtQd
y8lpq+LQLzw5lzlNCkATXdW60tdhIPORN7Q6H4RloDP4j9UOuE9BdRQ17gcCcnx8
l3yTOA+zyNjEbKrWyjcnZIrGVwkLKhzuC5ONHe/RQGLS7oM2RnUOLo69VfX1mG2g
MTj+J5MqZchqVZHexblBxuQc8a1XqlQD1sIIWIcjlii5SdL33daIOWozxPvtwgpO
OEQhUGMxCalbBh87qkO91JVIldzydLhA83OPYhsF1+j5SUOFVGYzG/UJevI14I0V
tbYZPE8Gva4gbJlJAqO/locaF415k+ZrvbWnBlDtYz6UqkZeiVOHpx6mz7d12ZWi
RdLq4w0jXlRaeCCBKXR1IXrDBhMK8gnow+RbUrYLKf4HjZmrNek+7J3NlZG9G/cL
L0kR86VIZL6gh6XAnTLOmstPFqEi9MxVw4Az0nod+t5Hh52N5Ym5f4YRApDp9ZyP
r/1v680kXzncL+TtOrXHW73PwgPBTbfd7qHKyOiDNAq9sF2Edo/XbIBsY2T6d0uz
35RkV/65OFLg05WIMR9OralW0jtl1fELrPg+KbSIdP1VUeHbXF0sFs+OgeF0njbe
RUPmEp1b0g==
=V/au
-----END PGP SIGNATURE-----