What's the difference between GCC deleting parts of your code, and an attacker hacking into the source code repository and deleting those parts of the code?
The C standards committee addressed the problem in 2009 with memset_s. [0] The GNU developers reject patches and state they hope this feature is never implemented. [1]
The bug fix is to stop using GCC for sensitive code. Use CompCert instead. https://github.com/AbsInt/CompCert
[0] http://www.open-std.org/jtc1/sc22/wg14/www/docs/n1381.pdf
[1] https://sourceware.org/ml/libc-alpha/2014-12/threads.html#00...