new file mode 100644
@@ -0,0 +1,88 @@
+From edc111a6831591f68b5355a08cc9df8be8f35304 Mon Sep 17 00:00:00 2001
+From: Nicholas Wilson <nicholas@nicholaswilson.me.uk>
+Date: Sat, 25 Oct 2025 10:50:27 +0100
+Subject: [PATCH] Write padding values to ensure pcre2_serialize_encode()
+ outputs defined values (#826)
+
+Fixes low-severity valgrind error reported in GHSA-q7rw-r7qq-2hx6.
+
+CVE: CVE-2026-89162
+Upstream-Status: Backport [https://github.com/PCRE2Project/pcre2/commit/edc111a6831591f68b5355a08cc9df8be8f35304]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/pcre2_compile_class.c | 17 +++++++----------
+ src/pcre2test_inc.h | 25 +++++++++++++++++++++++++
+ 2 files changed, 32 insertions(+), 10 deletions(-)
+
+diff --git a/src/pcre2_compile_class.c b/src/pcre2_compile_class.c
+index 9a1fc022..55b641c1 100644
+--- a/src/pcre2_compile_class.c
++++ b/src/pcre2_compile_class.c
+@@ -1802,17 +1802,14 @@ if ((xclass_props & XCLASS_REQUIRED) != 0)
+ PUT(code, 0, (uint32_t)(char_lists_size >> 1));
+ code += LINK_SIZE;
+
+-#if defined PCRE2_DEBUG || defined SUPPORT_VALGRIND
++ /* If we added padding to align the list, initialize the bytes to
++ defined values, so the library is valgrind-clean. It could also
++ be a security concern for clients calling into PCRE2 via bindings
++ from a memory-safe language, if pcre2_serialize_encode() exposes
++ uninitialized memory that may contain sensitive information. */
++
+ if ((char_lists_size & 0x2) != 0)
+- {
+- /* In debug the unused 16 bit value is set
+- to a fixed value and marked unused. */
+- ((uint16_t*)data)[-1] = 0x5555;
+-#ifdef SUPPORT_VALGRIND
+- VALGRIND_MAKE_MEM_NOACCESS(data - 2, 2);
+-#endif
+- }
+-#endif
++ ((uint16_t*)data)[-1] = 0xdead;
+
+ cb->char_lists_size =
+ CLIST_ALIGN_TO(char_lists_size, sizeof(uint32_t));
+diff --git a/src/pcre2test_inc.h b/src/pcre2test_inc.h
+index 8124e9ca..c4707417 100644
+--- a/src/pcre2test_inc.h
++++ b/src/pcre2test_inc.h
+@@ -2019,6 +2019,9 @@ uint32_t use_forbid_utf = forbid_utf;
+ PCRE2_SIZE patlen, full_patlen;
+ PCRE2_SIZE valgrind_access_length;
+ PCRE2_SIZE erroroffset;
++int32_t serialize_rc;
++uint8_t *serialized_bytes;
++PCRE2_SIZE serialized_size;
+
+ /* The perltest.sh script supports only / as a delimiter. */
+
+@@ -2966,6 +2969,28 @@ if ((pat_patctl.control2 & CTL2_NL_SET) != 0)
+ rc = show_pattern_info();
+ if (rc != PR_OK) return rc;
+
++/* Verify that the compiled structure can be serialized without generating
++memory errors. */
++
++serialize_rc = pcre2_serialize_encode((const pcre2_code **)&compiled_code, 1,
++ &serialized_bytes, &serialized_size, general_context);
++if (serialize_rc != 1)
++ {
++ cfprintf(clr_test_error, outfile, "** pcre2_serialize_encode() returned %d instead of 1\n",
++ serialize_rc);
++ return PR_ABEND;
++ }
++
++#if defined SUPPORT_VALGRIND
++if (VALGRIND_CHECK_MEM_IS_DEFINED(serialized_bytes, serialized_size) != 0)
++ {
++ cfprintf(clr_test_error, outfile, "** pcre2_serialize_encode() returned undefined data\n");
++ return PR_ABEND;
++ }
++#endif
++
++pcre2_serialize_free(serialized_bytes);
++
+ /* The "push" control requests that the compiled pattern be remembered on a
+ stack. This is mainly for testing the serialization functionality. */
+
@@ -14,6 +14,7 @@ LIC_FILES_CHKSUM = "file://LICENCE.md;md5=6720bf3bcff57543b915c2b22e526df0 \
SRC_URI = "${GITHUB_BASE_URI}/download/pcre2-${PV}/pcre2-${PV}.tar.bz2 \
file://run-ptest \
+ file://CVE-2026-89162.patch \
"
GITHUB_BASE_URI = "https://github.com/PCRE2Project/pcre2/releases"