CVE-2026-102010: Red Hat Enterprise Linux 10

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images: before 13.5.0-0.2.hum1 (fixed in 13.5.0-0.2.hum1); before 16.2.1-3.hum1 (fixed in 16.2.1-3.hum1)
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-09-28. Last modified 2026-10-02.