[PATCH] libstdc++: Fix use-after-free in pbds binary heap (CVE-2026-102010) [PR127656]
Tomasz Kaminski
tkaminsk@redhat.com
Tue Sep 29 11:54:14 GMT 2026
On Tue, Sep 29, 2026 at 1:02 PM Jonathan Wakely <jwakely@redhat.com> wrote:
> After reallocating the storage the m_a_entries pointer is left dangling
> and the new storage is leaked.
>
> libstdc++-v3/ChangeLog:
>
> PR libstdc++/127656
> * include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
> (erase_if): Update m_a_entries after reallocation.
> * testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc:
> New test.
> ---
>
> Tested x86_64-linux.
>
The fix makes sense for me, I have also validated that test crashes without
it.
LGTM.
>
> Backports needed too. Then we should delete the pb_ds stuff from trunk.
>
> .../detail/binary_heap_/erase_fn_imps.hpp | 1 +
> .../regression/priority_queues_erase_if.cc | 19 +++++++++++++++++++
> 2 files changed, 20 insertions(+)
> create mode 100644
> libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
>
> diff --git
> a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
> b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
> index 2e70ed5c663d..80d2cccbbf0b 100644
> --- a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
> +++ b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
> @@ -121,6 +121,7 @@ erase_if(Pred pred)
> entry_pointer new_entries = s_entry_allocator.allocate(new_size);
> std::copy(m_a_entries, m_a_entries + left, new_entries);
> s_entry_allocator.deallocate(m_a_entries, m_actual_size);
> + m_a_entries = new_entries;
> m_actual_size = new_size;
>
clear()/resize_for_erase_if_needed set size first, then the entries, but I
do not think that matters.
outside of visual consistency.
> resize_policy::notify_arbitrary(m_actual_size);
> }
> diff --git
> a/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
> b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
> new file mode 100644
> index 000000000000..30b8452eff96
> --- /dev/null
> +++
> b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
> @@ -0,0 +1,19 @@
> +// { dg-do run }
> +
> +// CVE-2026-201020 use-after-free in binary heap erase_if
> +
> +#include <ext/pb_ds/priority_queue.hpp>
> +
> +bool is_odd(int v) { return v & 1; }
> +
> +int main()
> +{
> + using __gnu_pbds::priority_queue;
> + using __gnu_pbds::binary_heap_tag;
> + priority_queue<int, std::less<int>, binary_heap_tag> q;
> + q.push(1);
> + q.push(2);
> + q.push(3);
> + q.erase_if(&is_odd);
> + q.clear();
> +}
> --
> 2.55.0
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://gcc.gnu.org/pipermail/libstdc++/attachments/20260929/2276330a/attachment.htm>
More information about the Libstdc++
mailing list