new file mode 100644
@@ -0,0 +1,26 @@
+From 40daa9996d616e66a75dea41ed2b18f2c3901b9f Mon Sep 17 00:00:00 2001
+From: Sorrachat <32319737+Sorrashut-K@users.noreply.github.com>
+Date: Fri, 14 Aug 2026 17:29:50 -0400
+Subject: [PATCH] lib: Fix inverted getentropy() return in
+ writeRandomBytes_getentropy
+
+CVE: CVE-2026-76956
+Upstream-Status: Backport [https://github.com/libexpat/libexpat/commit/40daa9996d616e66a75dea41ed2b18f2c3901b9f]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ lib/random_getentropy.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/lib/random_getentropy.c b/expat/lib/random_getentropy.c
+index d258df6a..ad8b1984 100644
+--- a/lib/random_getentropy.c
++++ b/lib/random_getentropy.c
+@@ -54,7 +54,7 @@
+ bool
+ writeRandomBytes_getentropy(void *target, size_t count) {
+ errno = 0;
+- const bool success = getentropy(target, count);
++ const bool success = (getentropy(target, count) == 0);
+ // MSan does not understand `getentropy`, so explain its effects
+ if (success)
+ MSAN_UNPOISON(target, count);
@@ -13,6 +13,7 @@ SRC_URI = "${GITHUB_BASE_URI}/download/R_${VERSION_TAG}/expat-${PV}.tar.bz2 \
file://CVE-2026-66046-01.patch \
file://CVE-2026-66046-02.patch \
file://CVE-2026-76641.patch \
+ file://CVE-2026-76956.patch \
"
GITHUB_BASE_URI = "https://github.com/libexpat/libexpat/releases/"