发现 GCC 中存在一个漏洞。当应用程序在 libstdc++ 中对二叉堆优先队列调用 erase_if 函数时,该库会重新分配存储空间,但未能更新其内部条目指针。攻击者若能够触发此操作,即可利用此处的释放后使用(use-after-free)漏洞,导致应用程序崩溃或潜在内存损坏,从而引发拒绝服务(DoS)攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
any |
affected | ||
| Red Hat | Red Hat Hardened Images | any |
affected |
any |
affected | ||
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
affected |
any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101292 | 8.2 HIGH | Artemis-core-client: unsafe reflection in apache activemq artemis federation message deser |
| CVE-2026-86330 | 7.2 HIGH | Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_intern |
| CVE-2026-97023 | 7.1 HIGH | Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy dir |
| CVE-2026-87114 | 7.1 HIGH | Kube-compare: container:// reference extraction runs the image entrypoint and silently esc |
| CVE-2026-96740 | 6.5 MEDIUM | Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka c |
| CVE-2026-97026 | 3.9 LOW | Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path |
| CVE-2026-101333 | 3.7 LOW | Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on brok |
| CVE-2026-97027 | 3.6 LOW | Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus |
| CVE-2026-97025 | 3.2 LOW | Flatpak: flatpak: world-readable oci authentication token in system-helper cache path |
No comments yet