@@ -74,6 +74,7 @@ SRC_URI = "${BASEURI} \
file://0025-gcc-testsuite-tweaks-for-mips-OE.patch \
file://0001-mapper-localhost-might-not-be-known.patch \
file://0001-Fix-check-for-working-assembler-gdwarf-4-option.patch \
+ file://0026-CVE-2026-102010.patch \
"
UNPACKDIR = "${TMPDIR}/work-shared/gcc-${PV}-${PR}/sources"
new file mode 100644
@@ -0,0 +1,71 @@
+From aaa8351f4d2e636f9680a1f0a8ebc2f0a60611e6 Mon Sep 17 00:00:00 2001
+From: Jonathan Wakely <jwakely@redhat.com>
+Date: Fri, 25 Sep 2026 18:14:34 +0100
+Subject: [PATCH] libstdc++: Fix use-after-free in pbds binary heap
+ (CVE-2026-102010) [PR127656]
+MIME-Version: 1.0
+Content-Type: text/plain; charset=utf-8
+Content-Transfer-Encoding: 8bit
+
+After reallocating the storage the m_a_entries pointer is left dangling
+and the new storage is leaked.
+
+libstdc++-v3/ChangeLog:
+
+ PR libstdc++/127656
+ * include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
+ (erase_if): Update m_a_entries after reallocation.
+ * testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc:
+ New test.
+
+CVE: CVE-2026-102010
+
+Upstream-Status: Backport [https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=aaa8351f4d2e636f9680a1f0a8ebc2f0a60611e6]
+
+Reviewed-by: Tomasz KamiĆski <tkaminsk@redhat.com>
+Signed-off-by: Hemanth Kumar M D <Hemanth.KumarMD@windriver.com>
+---
+ .../detail/binary_heap_/erase_fn_imps.hpp | 1 +
+ .../regression/priority_queues_erase_if.cc | 19 +++++++++++++++++++
+ 2 files changed, 20 insertions(+)
+ create mode 100644 libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
+
+diff --git a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
+index 2e70ed5c663..80d2cccbbf0 100644
+--- a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
++++ b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
+@@ -121,6 +121,7 @@ erase_if(Pred pred)
+ entry_pointer new_entries = s_entry_allocator.allocate(new_size);
+ std::copy(m_a_entries, m_a_entries + left, new_entries);
+ s_entry_allocator.deallocate(m_a_entries, m_actual_size);
++ m_a_entries = new_entries;
+ m_actual_size = new_size;
+ resize_policy::notify_arbitrary(m_actual_size);
+ }
+diff --git a/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
+new file mode 100644
+index 00000000000..30b8452eff9
+--- /dev/null
++++ b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
+@@ -0,0 +1,19 @@
++// { dg-do run }
++
++// CVE-2026-201020 use-after-free in binary heap erase_if
++
++#include <ext/pb_ds/priority_queue.hpp>
++
++bool is_odd(int v) { return v & 1; }
++
++int main()
++{
++ using __gnu_pbds::priority_queue;
++ using __gnu_pbds::binary_heap_tag;
++ priority_queue<int, std::less<int>, binary_heap_tag> q;
++ q.push(1);
++ q.push(2);
++ q.push(3);
++ q.erase_if(&is_odd);
++ q.clear();
++}
+--
+2.49.0