A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.
The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Hardened Images | RedHat | gcc13-main-13.5.0-0.2.hum1 | * |
| Red Hat Hardened Images | RedHat | gcc-main-16.2.1-3.hum1 | * |