Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package gcc7 for openSUSE:Factory checked in 
at 2026-10-01 16:45:37
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/gcc7 (Old)
 and      /work/SRC/openSUSE:Factory/.gcc7.new.1253 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "gcc7"

Thu Oct  1 16:45:37 2026 rev:50 rq:1381715 version:7.5.0+r278197

Changes:
--------
--- /work/SRC/openSUSE:Factory/gcc7/gcc7.changes        2026-05-12 
19:27:07.912239922 +0200
+++ /work/SRC/openSUSE:Factory/.gcc7.new.1253/gcc7.changes      2026-10-01 
16:46:40.616115003 +0200
@@ -1,0 +2,19 @@
+Wed Sep 30 06:38:23 UTC 2026 - Richard Biener <[email protected]>
+
+- Add gcc7-pr113258.patch to fix possible integer overflow with
+  aligned new operator.  [bsc#1282500] (CVE-2026-95619)
+
+-------------------------------------------------------------------
+Tue Sep 29 14:10:08 UTC 2026 - Richard Biener <[email protected]>
+
+- Add gcc7-pr127656.patch to fix use-after-free in
+  __gnu_pbds::priority_queue.  [bsc#1283123] (CVE-2026-102010)
+- Add gcc7-libsanitizer-scc.patch to fix build with new glibc.
+
+-------------------------------------------------------------------
+Tue Jun  9 11:27:52 UTC 2026 - Richard Biener <[email protected]>
+
+- Add gcc7-pr100114.patch to fix ASAN behavior when libsanitizer
+  is built against glibc 2.34 or later.  [bsc#1267946]
+
+-------------------------------------------------------------------

New:
----
  gcc7-libsanitizer-scc.patch
  gcc7-pr100114.patch
  gcc7-pr113258.patch
  gcc7-pr127656.patch
  pre_checkin.sh

----------(New B)----------
  New:  __gnu_pbds::priority_queue.  [bsc#1283123] (CVE-2026-102010)
- Add gcc7-libsanitizer-scc.patch to fix build with new glibc.
  New:
- Add gcc7-pr100114.patch to fix ASAN behavior when libsanitizer
  is built against glibc 2.34 or later.  [bsc#1267946]
  New:
- Add gcc7-pr113258.patch to fix possible integer overflow with
  aligned new operator.  [bsc#1282500] (CVE-2026-95619)
  New:
- Add gcc7-pr127656.patch to fix use-after-free in
  __gnu_pbds::priority_queue.  [bsc#1283123] (CVE-2026-102010)
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ cross-aarch64-gcc7.spec ++++++
--- /var/tmp/diff_new_pack.qfQhBg/_old  2026-10-01 16:46:46.147346830 +0200
+++ /var/tmp/diff_new_pack.qfQhBg/_new  2026-10-01 16:46:46.151346998 +0200
@@ -162,6 +162,10 @@
 Patch71:        gcc7-libsanitizer-termio.patch
 Patch72:        gcc7-pr58150.patch
 Patch73:        gcc7-pr105225.patch
+Patch74:        gcc7-pr100114.patch
+Patch75:        gcc7-libsanitizer-scc.patch
+Patch76:        gcc7-pr127656.patch
+Patch77:        gcc7-pr113258.patch
 # A set of patches from the RH srpm
 Patch51:        gcc41-ppc32-retaddr.patch
 # Some patches taken from Debian
@@ -370,6 +374,10 @@
 %endif
 %patch -P 72 -p1
 %patch -P 73 -p1
+%patch -P 74 -p1
+%patch -P 75 -p1
+%patch -P 76 -p1
+%patch -P 77 -p1
 %patch -P 51
 %patch -P 60
 %patch -P 61

cross-arm-gcc7.spec: same change
cross-arm-none-gcc7-bootstrap.spec: same change
cross-arm-none-gcc7.spec: same change
cross-avr-gcc7-bootstrap.spec: same change
cross-avr-gcc7.spec: same change
cross-hppa-gcc7.spec: same change
cross-i386-gcc7.spec: same change
cross-m68k-gcc7.spec: same change
cross-mips-gcc7.spec: same change
cross-nvptx-gcc7.spec: same change
cross-ppc64-gcc7.spec: same change
cross-ppc64le-gcc7.spec: same change
cross-rx-gcc7-bootstrap.spec: same change
cross-rx-gcc7.spec: same change
cross-s390x-gcc7.spec: same change
cross-sparc-gcc7.spec: same change
cross-sparc64-gcc7.spec: same change
cross-x86_64-gcc7.spec: same change
gcc7-testresults.spec: same change
++++++ gcc7.spec ++++++
--- /var/tmp/diff_new_pack.qfQhBg/_old  2026-10-01 16:46:47.124387780 +0200
+++ /var/tmp/diff_new_pack.qfQhBg/_new  2026-10-01 16:46:47.130388032 +0200
@@ -342,6 +342,10 @@
 Patch71:        gcc7-libsanitizer-termio.patch
 Patch72:        gcc7-pr58150.patch
 Patch73:        gcc7-pr105225.patch
+Patch74:        gcc7-pr100114.patch
+Patch75:        gcc7-libsanitizer-scc.patch
+Patch76:        gcc7-pr127656.patch
+Patch77:        gcc7-pr113258.patch
 # A set of patches from the RH srpm
 Patch51:        gcc41-ppc32-retaddr.patch
 # Some patches taken from Debian
@@ -1895,6 +1899,10 @@
 %endif
 %patch -P 72 -p1
 %patch -P 73 -p1
+%patch -P 74 -p1
+%patch -P 75 -p1
+%patch -P 76 -p1
+%patch -P 77 -p1
 %patch -P 51
 %patch -P 60
 %patch -P 61

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.qfQhBg/_old  2026-10-01 16:46:47.269393857 +0200
+++ /var/tmp/diff_new_pack.qfQhBg/_new  2026-10-01 16:46:47.274394067 +0200
@@ -1,5 +1,5 @@
-mtime: 1778507476
-commit: fd66ab96a44f19170e1f1f111a31c67e0503c6c0aedf6ab4b07071649d925033
+mtime: 1790776997
+commit: 3c4452de3175b4fe98046772540c1dabd658f004e26a53ef2d8cca2d81c65d6e
 url: https://src.opensuse.org/gcc/gcc7.git
 revision: main
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-30 16:03:17.000000000 +0200
@@ -0,0 +1 @@
+.osc
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/pre_checkin.sh new/pre_checkin.sh
--- old/pre_checkin.sh  1970-01-01 01:00:00.000000000 +0100
+++ new/pre_checkin.sh  2026-09-30 16:03:17.000000000 +0200
@@ -0,0 +1,31 @@
+#!/bin/bash
+# This script is called automatically during autobuild checkin.
+
+case $0 in
+  \./*)
+    here=$PWD
+    ;;
+  */*)
+    here=${0%/*}
+    ;;
+  *)
+    here=$PWD
+    ;;
+esac
+case ${here##*/} in
+  gcc*.*)
+    # Handle maintainance projects with .$REPO suffix
+    suffix=${here##*/}
+    suffix=${suffix%%\.*}
+    set ${suffix#gcc}
+    ;;
+  gcc-*)
+    suffix=${here##*/}
+    set ${suffix#*-}-
+    ;;
+  gcc[0-9]*)
+    suffix=${here##*/}
+    set ${suffix#gcc}
+    ;;
+esac
+. ${here}/change_spec

++++++ gcc.spec.in ++++++
--- /var/tmp/diff_new_pack.qfQhBg/_old  2026-10-01 16:46:47.633409114 +0200
+++ /var/tmp/diff_new_pack.qfQhBg/_new  2026-10-01 16:46:47.637409282 +0200
@@ -349,6 +349,10 @@
 Patch71:       gcc7-libsanitizer-termio.patch
 Patch72:       gcc7-pr58150.patch
 Patch73:       gcc7-pr105225.patch
+Patch74:       gcc7-pr100114.patch
+Patch75:       gcc7-libsanitizer-scc.patch
+Patch76:       gcc7-pr127656.patch
+Patch77:       gcc7-pr113258.patch
 # A set of patches from the RH srpm
 Patch51:       gcc41-ppc32-retaddr.patch
 # Some patches taken from Debian
@@ -1169,6 +1173,10 @@
 %endif
 %patch -P 72 -p1
 %patch -P 73 -p1
+%patch -P 74 -p1
+%patch -P 75 -p1
+%patch -P 76 -p1
+%patch -P 77 -p1
 %patch -P 51
 %patch -P 60
 %patch -P 61

++++++ gcc7-libsanitizer-scc.patch ++++++
Remove the use of <linux/scc.h> from libsanitizer: the header was removed
from the kernel together with the SCC driver (Linux 6.7). Same treatment as
gcc7-sanitizer-cyclades.patch.

diff -ur a/libsanitizer/sanitizer_common/sanitizer_platform_limits_posix.cc 
b/libsanitizer/sanitizer_common/sanitizer_platform_limits_posix.cc
--- a/libsanitizer/sanitizer_common/sanitizer_platform_limits_posix.cc  
2018-06-07 13:50:45.620438463 +0200
+++ b/libsanitizer/sanitizer_common/sanitizer_platform_limits_posix.cc  
2026-09-28 10:47:48.738344884 +0200
@@ -160,7 +160,6 @@
 #include <linux/lp.h>
 #include <linux/mroute.h>
 #include <linux/mroute6.h>
-#include <linux/scc.h>
 #include <linux/serial.h>
 #include <sys/msg.h>
 #include <sys/ipc.h>
@@ -467,8 +466,6 @@
   unsigned struct_kbsentry_sz = sizeof(struct kbsentry);
   unsigned struct_mtconfiginfo_sz = sizeof(struct mtconfiginfo);
   unsigned struct_nr_parms_struct_sz = sizeof(struct nr_parms_struct);
-  unsigned struct_scc_modem_sz = sizeof(struct scc_modem);
-  unsigned struct_scc_stat_sz = sizeof(struct scc_stat);
   unsigned struct_serial_multiport_struct_sz
       = sizeof(struct serial_multiport_struct);
   unsigned struct_serial_struct_sz = sizeof(struct serial_struct);
diff -ur a/libsanitizer/sanitizer_common/sanitizer_platform_limits_posix.h 
b/libsanitizer/sanitizer_common/sanitizer_platform_limits_posix.h
--- a/libsanitizer/sanitizer_common/sanitizer_platform_limits_posix.h   
2017-01-11 09:34:21.102969781 +0100
+++ b/libsanitizer/sanitizer_common/sanitizer_platform_limits_posix.h   
2026-09-28 10:47:48.739945857 +0200
@@ -1009,8 +1009,6 @@
   extern unsigned struct_kbsentry_sz;
   extern unsigned struct_mtconfiginfo_sz;
   extern unsigned struct_nr_parms_struct_sz;
-  extern unsigned struct_scc_modem_sz;
-  extern unsigned struct_scc_stat_sz;
   extern unsigned struct_serial_multiport_struct_sz;
   extern unsigned struct_serial_struct_sz;
   extern unsigned struct_sockaddr_ax25_sz;

++++++ gcc7-pr100114.patch ++++++
>From dfb90632731eb657bccde31d03c978a1c69610cd Mon Sep 17 00:00:00 2001
From: Richard Biener <[email protected]>
Date: Sat, 17 Apr 2021 11:27:14 +0200
Subject: [PATCH] sanitizer: Fix asan against glibc 2.34 [PR100114]
To: [email protected]

From: Jakub Jelinek <[email protected]>

As mentioned in the PR, SIGSTKSZ is no longer a compile time constant in
glibc 2.34 and later, so
static const uptr kAltStackSize = SIGSTKSZ * 4;
needs dynamic initialization, but is used by a function called indirectly
from .preinit_array and therefore before the variable is constructed.
This results in using 0 size instead and all asan instrumented programs
die with:
==91==ERROR: AddressSanitizer failed to allocate 0x0 (0) bytes of 
SetAlternateSignalStack (error code: 22)

Here is a cherry-pick from upstream to fix this.

2021-04-17  Jakub Jelinek  <[email protected]>

        PR sanitizer/100114
        * sanitizer_common/sanitizer_posix_libcdep.cpp: Cherry-pick
        llvm-project revisions 82150606fb11d28813ae6da1101f5bda638165fe
        and b93629dd335ffee2fc4b9b619bf86c3f9e6b0023.

(cherry picked from commit d9f462fb372fb02da032cefd6b091d7582c425ae)
---
 .../sanitizer_common/sanitizer_posix_libcdep.cc     | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

diff --git a/libsanitizer/sanitizer_common/sanitizer_posix_libcdep.cc 
b/libsanitizer/sanitizer_common/sanitizer_posix_libcdep.cc
index 335aad1660e..359566a0189 100644
--- a/libsanitizer/sanitizer_common/sanitizer_posix_libcdep.cc
+++ b/libsanitizer/sanitizer_common/sanitizer_posix_libcdep.cc
@@ -153,7 +153,11 @@ bool SupportsColoredOutput(fd_t fd) {
 
 #if !SANITIZER_GO
 // TODO(glider): different tools may require different altstack size.
-static const uptr kAltStackSize = SIGSTKSZ * 4;  // SIGSTKSZ is not enough.
+static uptr GetAltStackSize() {
+  // SIGSTKSZ is not enough.
+  static const uptr kAltStackSize = SIGSTKSZ * 4;
+  return kAltStackSize;
+}
 
 void SetAlternateSignalStack() {
   stack_t altstack, oldstack;
@@ -164,10 +168,9 @@ void SetAlternateSignalStack() {
   // TODO(glider): the mapped stack should have the MAP_STACK flag in the
   // future. It is not required by man 2 sigaltstack now (they're using
   // malloc()).
-  void* base = MmapOrDie(kAltStackSize, __func__);
-  altstack.ss_sp = (char*) base;
+  altstack.ss_size = GetAltStackSize();
+  altstack.ss_sp = (char *)MmapOrDie(altstack.ss_size, __func__);
   altstack.ss_flags = 0;
-  altstack.ss_size = kAltStackSize;
   CHECK_EQ(0, sigaltstack(&altstack, nullptr));
 }
 
@@ -175,7 +178,7 @@ void UnsetAlternateSignalStack() {
   stack_t altstack, oldstack;
   altstack.ss_sp = nullptr;
   altstack.ss_flags = SS_DISABLE;
-  altstack.ss_size = kAltStackSize;  // Some sane value required on Darwin.
+  altstack.ss_size = GetAltStackSize();  // Some sane value required on Darwin.
   CHECK_EQ(0, sigaltstack(&altstack, &oldstack));
   UnmapOrDie(oldstack.ss_sp, oldstack.ss_size);
 }
-- 
2.51.0


++++++ gcc7-pr113258.patch ++++++
>From 2f39bbe344ff5d38474dd4d94ad9d7c8af5b7ff5 Mon Sep 17 00:00:00 2001
From: Richard Biener <[email protected]>
Date: Tue, 9 Jan 2024 15:22:46 +0000
Subject: [PATCH 1/2] libstdc++: Prefer posix_memalign for aligned-new
 [PR113258]
To: [email protected]

From: Jonathan Wakely <[email protected]>

As described in PR libstdc++/113258 there are old versions of tcmalloc
which replace malloc and related APIs, but do not repalce aligned_alloc
because it didn't exist at the time they were released. This means that
when operator new(size_t, align_val_t) uses aligned_alloc to obtain
memory, it comes from libc's aligned_alloc not from tcmalloc. But when
operator delete(void*, size_t, align_val_t) uses free to deallocate the
memory, that goes to tcmalloc's replacement version of free, which
doesn't know how to free it.

If we give preference to the older posix_memalign instead of
aligned_alloc then we're more likely to use a function that will be
compatible with the replacement version of free. Because posix_memalign
has been around for longer, it's more likely that old third-party malloc
replacements will also replace posix_memalign alongside malloc and free.

libstdc++-v3/ChangeLog:

        PR libstdc++/113258
        * libsupc++/new_opa.cc: Prefer to use posix_memalign if
        available.

(cherry picked from commit f50f2efae9fb0965d8ccdb62cfdb698336d5a933)
---
 libstdc++-v3/libsupc++/new_opa.cc | 40 ++++++++++++++++++++++++-------
 1 file changed, 32 insertions(+), 8 deletions(-)

diff --git a/libstdc++-v3/libsupc++/new_opa.cc 
b/libstdc++-v3/libsupc++/new_opa.cc
index d7461227c29..623c674206e 100644
--- a/libstdc++-v3/libsupc++/new_opa.cc
+++ b/libstdc++-v3/libsupc++/new_opa.cc
@@ -42,14 +42,31 @@ extern "C" void *memalign(std::size_t boundary, std::size_t 
size);
 using std::new_handler;
 using std::bad_alloc;
 
+#if ! _GLIBCXX_HOSTED
+using std::size_t;
+extern "C"
+{
+# if _GLIBCXX_HAVE_POSIX_MEMALIGN
+  void *posix_memalign(void **, size_t alignment, size_t size);
+# elif _GLIBCXX_HAVE_ALIGNED_ALLOC
+  void *aligned_alloc(size_t alignment, size_t size);
+# elif _GLIBCXX_HAVE__ALIGNED_MALLOC
+  void *_aligned_malloc(size_t size, size_t alignment);
+# elif _GLIBCXX_HAVE_MEMALIGN
+  void *memalign(size_t alignment, size_t size);
+# else
+  // A freestanding C runtime may not provide "malloc" -- but there is no
+  // other reasonable way to implement "operator new".
+  void *malloc(size_t);
+# endif
+}
+#endif
+
 namespace __gnu_cxx {
-#if _GLIBCXX_HAVE_ALIGNED_ALLOC
-using ::aligned_alloc;
-#elif _GLIBCXX_HAVE__ALIGNED_MALLOC
-static inline void*
-aligned_alloc (std::size_t al, std::size_t sz)
-{ return _aligned_malloc(sz, al); }
-#elif _GLIBCXX_HAVE_POSIX_MEMALIGN
+// Prefer posix_memalign if available, because it's older than aligned_alloc
+// and so more likely to be provided by replacement malloc libraries that
+// predate the addition of aligned_alloc. See PR libstdc++/113258.
+#if _GLIBCXX_HAVE_POSIX_MEMALIGN
 static inline void*
 aligned_alloc (std::size_t al, std::size_t sz)
 {
@@ -63,6 +80,12 @@ aligned_alloc (std::size_t al, std::size_t sz)
     return ptr;
   return nullptr;
 }
+#elif _GLIBCXX_HAVE_ALIGNED_ALLOC
+using ::aligned_alloc;
+#elif _GLIBCXX_HAVE__ALIGNED_MALLOC
+static inline void*
+aligned_alloc (std::size_t al, std::size_t sz)
+{ return _aligned_malloc(sz, al); }
 #elif _GLIBCXX_HAVE_MEMALIGN
 static inline void*
 aligned_alloc (std::size_t al, std::size_t sz)
@@ -113,7 +136,8 @@ operator new (std::size_t sz, std::align_val_t al)
   if (__builtin_expect (sz == 0, false))
     sz = 1;
 
-#if _GLIBCXX_HAVE_ALIGNED_ALLOC
+#if _GLIBCXX_HAVE_POSIX_MEMALIGN
+#elif _GLIBCXX_HAVE_ALIGNED_ALLOC
 # if defined _AIX || defined __APPLE__
   /* AIX 7.2.0.0 aligned_alloc incorrectly has posix_memalign's requirement
    * that alignment is a multiple of sizeof(void*).
-- 
2.51.0


>From cd596620ecc72c6b034f87e1f8bf9860e62addeb Mon Sep 17 00:00:00 2001
From: Richard Biener <[email protected]>
Date: Fri, 14 Jun 2024 12:10:48 +0100
Subject: [PATCH 2/2] libstdc++: Fix declaration of posix_memalign for
 freestanding
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
To: [email protected]

From: Jonathan Wakely <[email protected]>

Thanks to Jérôme Duval for noticing this.

libstdc++-v3/ChangeLog:

        * libsupc++/new_opa.cc [!_GLIBCXX_HOSTED]: Fix declaration of
        posix_memalign.

(cherry picked from commit 161efd677458f20d13ee1018a4d5e3964febd508)
---
 libstdc++-v3/libsupc++/new_opa.cc | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libstdc++-v3/libsupc++/new_opa.cc 
b/libstdc++-v3/libsupc++/new_opa.cc
index 623c674206e..5f3c1d6b775 100644
--- a/libstdc++-v3/libsupc++/new_opa.cc
+++ b/libstdc++-v3/libsupc++/new_opa.cc
@@ -47,7 +47,7 @@ using std::size_t;
 extern "C"
 {
 # if _GLIBCXX_HAVE_POSIX_MEMALIGN
-  void *posix_memalign(void **, size_t alignment, size_t size);
+  int posix_memalign(void **, size_t alignment, size_t size);
 # elif _GLIBCXX_HAVE_ALIGNED_ALLOC
   void *aligned_alloc(size_t alignment, size_t size);
 # elif _GLIBCXX_HAVE__ALIGNED_MALLOC
-- 
2.51.0


++++++ gcc7-pr127656.patch ++++++
>From 656307d155f25e73d6c0b6dea1cd6491b37cdd17 Mon Sep 17 00:00:00 2001
From: Richard Biener <[email protected]>
Date: Fri, 25 Sep 2026 18:14:34 +0100
Subject: [PATCH] libstdc++: Fix use-after-free in pbds binary heap
 (CVE-2026-102010) [PR127656]
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
To: [email protected]

From: Jonathan Wakely <[email protected]>

After reallocating the storage the m_a_entries pointer is left dangling
and the new storage is leaked.

libstdc++-v3/ChangeLog:

        PR libstdc++/127656
        * include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
        (erase_if): Update m_a_entries after reallocation.
        * testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc:
        New test.

Reviewed-by: Tomasz Kamiński <[email protected]>
(cherry picked from commit aaa8351f4d2e636f9680a1f0a8ebc2f0a60611e6)
---
 .../detail/binary_heap_/erase_fn_imps.hpp     |  1 +
 .../regression/priority_queues_erase_if.cc    | 19 +++++++++++++++++++
 2 files changed, 20 insertions(+)
 create mode 100644 
libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc

diff --git 
a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp 
b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
index 3f11de81016..5b17db5527b 100644
--- a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
+++ b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
@@ -119,6 +119,7 @@ erase_if(Pred pred)
       entry_pointer new_entries = s_entry_allocator.allocate(new_size);
       std::copy(m_a_entries, m_a_entries + left, new_entries);
       s_entry_allocator.deallocate(m_a_entries, m_actual_size);
+      m_a_entries = new_entries;
       m_actual_size = new_size;
       resize_policy::notify_arbitrary(m_actual_size);
     }
diff --git 
a/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc 
b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
new file mode 100644
index 00000000000..30b8452eff9
--- /dev/null
+++ b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
@@ -0,0 +1,19 @@
+// { dg-do run }
+
+// CVE-2026-201020 use-after-free in binary heap erase_if
+
+#include <ext/pb_ds/priority_queue.hpp>
+
+bool is_odd(int v) { return v & 1; }
+
+int main()
+{
+  using __gnu_pbds::priority_queue;
+  using __gnu_pbds::binary_heap_tag;
+  priority_queue<int, std::less<int>, binary_heap_tag> q;
+  q.push(1);
+  q.push(2);
+  q.push(3);
+  q.erase_if(&is_odd);
+  q.clear();
+}
-- 
2.51.0


++++++ pre_checkin.sh ++++++
#!/bin/bash
# This script is called automatically during autobuild checkin.

case $0 in
  \./*)
    here=$PWD
    ;;
  */*)
    here=${0%/*}
    ;;
  *)
    here=$PWD
    ;;
esac
case ${here##*/} in
  gcc*.*)
    # Handle maintainance projects with .$REPO suffix
    suffix=${here##*/}
    suffix=${suffix%%\.*}
    set ${suffix#gcc}
    ;;
  gcc-*)
    suffix=${here##*/}
    set ${suffix#*-}-
    ;;
  gcc[0-9]*)
    suffix=${here##*/}
    set ${suffix#gcc}
    ;;
esac
. ${here}/change_spec

Reply via email to