[PATCH] libstdc++: Fix use-after-free in pbds binary heap (CVE-2026-102010) [PR127656]

Tomasz Kaminski tkaminsk@redhat.com
Tue Sep 29 11:54:14 GMT 2026


On Tue, Sep 29, 2026 at 1:02 PM Jonathan Wakely <jwakely@redhat.com> wrote:

> After reallocating the storage the m_a_entries pointer is left dangling
> and the new storage is leaked.
>
> libstdc++-v3/ChangeLog:
>
>         PR libstdc++/127656
>         * include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
>         (erase_if): Update m_a_entries after reallocation.
>         * testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc:
>         New test.
> ---
>
> Tested x86_64-linux.
>
The fix makes sense for me, I have also validated that test crashes without
it.
LGTM.

>
> Backports needed too. Then we should delete the pb_ds stuff from trunk.
>
>  .../detail/binary_heap_/erase_fn_imps.hpp     |  1 +
>  .../regression/priority_queues_erase_if.cc    | 19 +++++++++++++++++++
>  2 files changed, 20 insertions(+)
>  create mode 100644
> libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
>
> diff --git
> a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
> b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
> index 2e70ed5c663d..80d2cccbbf0b 100644
> --- a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
> +++ b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
> @@ -121,6 +121,7 @@ erase_if(Pred pred)
>        entry_pointer new_entries = s_entry_allocator.allocate(new_size);
>        std::copy(m_a_entries, m_a_entries + left, new_entries);
>        s_entry_allocator.deallocate(m_a_entries, m_actual_size);
> +      m_a_entries = new_entries;
>        m_actual_size = new_size;
>
clear()/resize_for_erase_if_needed set size first, then the entries, but I
do not think that matters.
outside of visual consistency.

>        resize_policy::notify_arbitrary(m_actual_size);
>      }
> diff --git
> a/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
> b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
> new file mode 100644
> index 000000000000..30b8452eff96
> --- /dev/null
> +++
> b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
> @@ -0,0 +1,19 @@
> +// { dg-do run }
> +
> +// CVE-2026-201020 use-after-free in binary heap erase_if
> +
> +#include <ext/pb_ds/priority_queue.hpp>
> +
> +bool is_odd(int v) { return v & 1; }
> +
> +int main()
> +{
> +  using __gnu_pbds::priority_queue;
> +  using __gnu_pbds::binary_heap_tag;
> +  priority_queue<int, std::less<int>, binary_heap_tag> q;
> +  q.push(1);
> +  q.push(2);
> +  q.push(3);
> +  q.erase_if(&is_odd);
> +  q.clear();
> +}
> --
> 2.55.0
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://gcc.gnu.org/pipermail/libstdc++/attachments/20260929/2276330a/attachment.htm>


More information about the Libstdc++ mailing list