DEBIAN-CVE-2026-102010

Source
https://security-tracker.debian.org/tracker/CVE-2026-102010
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-102010
Upstream
  • CVE-2026-102010
Published
2026-09-28T19:16:48Z
Modified
2026-10-01T08:47:30Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.

References

Affected packages

Debian:12
gcc-12

Package

Name
gcc-12
Purl
pkg:deb/debian/gcc-12?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

12.*
12.2.0-14
12.2.0-14+deb12u1
12.2.0-14+hurd.1
12.2.0-14+loong64
12.2.0-14+loong64.1
12.2.0-15
12.2.0-16
12.2.0-17
12.2.0-18
12.3.0-1
12.3.0-2
12.3.0-3~exp1
12.3.0-3
12.3.0-4
12.3.0-5
12.3.0-6
12.3.0-7
12.3.0-8
12.3.0-9
12.3.0-10
12.3.0-11
12.3.0-12
12.3.0-13
12.3.0-14
12.3.0-15
12.3.0-16
12.3.0-17
12.4.0-1
12.4.0-2
12.4.0-3
12.4.0-4
12.4.0-5
12.4.0-6
12.4.0-7
12.4.0-8~alpha
12.4.0-8
12.5.0-1
12.5.0-2
12.5.0-3
12.5.0-4
12.5.0-5
12.5.0-6
12.5.0-7
12.5.0-8
12.5.0-9

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"
Debian:13
gcc-12

Package

Name
gcc-12
Purl
pkg:deb/debian/gcc-12?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

12.*
12.4.0-5
12.4.0-6
12.4.0-7
12.4.0-8~alpha
12.4.0-8
12.5.0-1
12.5.0-2
12.5.0-3
12.5.0-4
12.5.0-5
12.5.0-6
12.5.0-7
12.5.0-8
12.5.0-9

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"
gcc-14

Package

Name
gcc-14
Purl
pkg:deb/debian/gcc-14?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

14.*
14.2.0-19
14.2.0-20
14.2.0-21
14.2.0-22
14.2.0-23
14.2.0-24
14.2.0-25
14.3.0-1
14.3.0-2
14.3.0-3
14.3.0-4
14.3.0-5
14.3.0-6
14.3.0-7
14.3.0-8
14.3.0-9
14.3.0-10
14.3.0-11
14.3.0-12
14.3.0-13
14.3.0-14
14.3.0-15
14.3.0-16
14.4.0-1
14.4.0-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"
Debian:14
gcc-12

Package

Name
gcc-12
Purl
pkg:deb/debian/gcc-12?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

12.*
12.4.0-5
12.4.0-6
12.4.0-7
12.4.0-8~alpha
12.4.0-8
12.5.0-1
12.5.0-2
12.5.0-3
12.5.0-4
12.5.0-5
12.5.0-6
12.5.0-7
12.5.0-8
12.5.0-9

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"
gcc-14

Package

Name
gcc-14
Purl
pkg:deb/debian/gcc-14?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

14.*
14.2.0-19
14.2.0-20
14.2.0-21
14.2.0-22
14.2.0-23
14.2.0-24
14.2.0-25
14.3.0-1
14.3.0-2
14.3.0-3
14.3.0-4
14.3.0-5
14.3.0-6
14.3.0-7
14.3.0-8
14.3.0-9
14.3.0-10
14.3.0-11
14.3.0-12
14.3.0-13
14.3.0-14
14.3.0-15
14.3.0-16
14.4.0-1
14.4.0-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"
gcc-15

Package

Name
gcc-15
Purl
pkg:deb/debian/gcc-15?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
15-20241128-1
15-20241214-1
15-20241220-1
15-20241231-1
15-20250112-1
15-20250114-1
15-20250130-1
15-20250130-2
15-20250203-1
15-20250208-1
15-20250213-1
15-20250220-1
15-20250315-1
15-20250319-1
15-20250329-1
15-20250406-1
15-20250423-1
15.*
15.1.0-1
15.1.0-2
15.1.0-3
15.1.0-4
15.1.0-5
15.1.0-6
15.1.0-7
15.1.0-8
15.1.0-8+sh4
15.1.0-8+sh4.1
15.1.0-9
15.1.0-10
15.1.0-11
15.2.0-1
15.2.0-2
15.2.0-3
15.2.0-4
15.2.0-5
15.2.0-6
15.2.0-7
15.2.0-8
15.2.0-9
15.2.0-10
15.2.0-11
15.2.0-12
15.2.0-13
15.2.0-14
15.2.0-15
15.2.0-16
15.2.0-17
15.3.0-1
15.3.0-2
15.3.0-3
15.3.0-4

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"
gcc-16

Package

Name
gcc-16
Purl
pkg:deb/debian/gcc-16?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

Other
16-20251130-1
16-20251202-1
16-20251210-1
16-20251214-1
16-20260119-1
16-20260203-1
16-20260203-2
16-20260207-1
16-20260207-2
16-20260208-1
16-20260217-1
16-20260226-1
16-20260307-1
16-20260308-1
16-20260308-1+sh4
16-20260315-1
16-20260322-1
16-20260423-1
16-20260425-1
16.*
16.1.0-1
16.1.0-2
16.1.0-3
16.2.0-1
16.2.0-2
16.2.0-3

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-102010.json"