Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102010— Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

发现 GCC 中存在一个漏洞。当应用程序在 libstdc++ 中对二叉堆优先队列调用 erase_if 函数时,该库会重新分配存储空间,但未能更新其内部条目指针。攻击者若能够触发此操作,即可利用此处的释放后使用(use-after-free)漏洞,导致应用程序崩溃或潜在内存损坏,从而引发拒绝服务(DoS)攻击。

CVSS 7.0 · High

Affected Version Matrix 29

VendorProduct Version RangeStatus
Red Hat Red Hat Enterprise Linux 10 any affected
any affected
any affected
any affected
any affected
Red Hat Red Hat Enterprise Linux 6 any affected
any affected
any affected
any affected
any affected
Red Hat Red Hat Enterprise Linux 7 any affected
any affected
any affected
any affected
Red Hat Red Hat Enterprise Linux 8 any affected
any affected
any affected
any affected
any affected
Red Hat Red Hat Enterprise Linux 9 any affected
any affected
any affected
any affected
any affected
any affected
Red Hat Red Hat Hardened Images any affected
any affected
Red Hat Red Hat OpenShift Container Platform 4 any affected
any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102010

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
无效指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-102010

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102010

请登录查看更多情报信息。

Other References for CVE-2026-102010 (2)

Same Patch Batch · Red Hat · 2026-09-28 · 10 CVEs total

CVE-2026-101292 8.2 HIGH Artemis-core-client: unsafe reflection in apache activemq artemis federation message deser
CVE-2026-86330 7.2 HIGH Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_intern
CVE-2026-97023 7.1 HIGH Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy dir
CVE-2026-87114 7.1 HIGH Kube-compare: container:// reference extraction runs the image entrypoint and silently esc
CVE-2026-96740 6.5 MEDIUM Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka c
CVE-2026-97026 3.9 LOW Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path
CVE-2026-101333 3.7 LOW Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on brok
CVE-2026-97027 3.6 LOW Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus
CVE-2026-97025 3.2 LOW Flatpak: flatpak: world-readable oci authentication token in system-helper cache path

IV. Related Vulnerabilities

V. Comments for CVE-2026-102010

No comments yet


Leave a comment