There are 2 open security issues in trixie.
1 important issue:
- CVE-2026-95619:
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
1 issue left for the package maintainer to handle:
- CVE-2026-102010:
(needs triaging)
A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.
You can find information about how to handle this issue in the security team's documentation.