CVE-2026-102010: Red Hat Enterprise Linux 10
High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Hardened Images: before 13.5.0-0.2.hum1 (fixed in 13.5.0-0.2.hum1); before 16.2.1-3.hum1 (fixed in 16.2.1-3.hum1)
- Red Hat Red Hat Openshift Container Platform 4
Published 2026-09-28. Last modified 2026-10-02.