This breaks the build when nthttp2 PACKAGECONFIG is enabled, because
curl_share.h included here was renamed from share.h in newer curl
8.22:
https://github.com/curl/curl/commit/3887069c661b40e76b053a4867eb565d4761ab3e
8.7.1 version in scarthgap fails with:
curl-8.7.1/lib/http2.c:50:10: fatal error: 'curl_share.h' file not found

Using share.h instead of curl_share.h fixes the include, but then it fails with
curl-8.7.1/lib/http2.c:781:15: error: call to undeclared function
'Curl_share_easy_link'; ISO C99 and later do not support implicit
function declarations [-Wimplicit-function-declaration]

Curl_share_easy_link was added in 8.20 with:
https://github.com/curl/curl/commit/82009c4220774417c821496affa4aa834c028b68
and that will be a bit more difficult to backport.

Please drop this one from the PR until it's resolved.

Cheers,

On Wed, Sep 23, 2026 at 11:12 AM Yoann Congal via
lists.openembedded.org <[email protected]>
wrote:
>
> From: Siddharth Doshi <[email protected]>
>
> Picking patch as per [1], and same patch is mentioned in [2]
>
> [1] https://curl.se/docs/CVE-2026-18924.html
> [2] https://security-tracker.debian.org/tracker/CVE-2026-18924
>
> Signed-off-by: Siddharth Doshi <[email protected]>
> Signed-off-by: Yoann Congal <[email protected]>
> ---
>  .../curl/curl/CVE-2026-18924.patch            | 39 +++++++++++++++++++
>  meta/recipes-support/curl/curl_8.7.1.bb       |  1 +
>  2 files changed, 40 insertions(+)
>  create mode 100644 meta/recipes-support/curl/curl/CVE-2026-18924.patch
>
> diff --git a/meta/recipes-support/curl/curl/CVE-2026-18924.patch 
> b/meta/recipes-support/curl/curl/CVE-2026-18924.patch
> new file mode 100644
> index 00000000000..28934ababee
> --- /dev/null
> +++ b/meta/recipes-support/curl/curl/CVE-2026-18924.patch
> @@ -0,0 +1,39 @@
> +From 90325ff0444cbdff368bda5d26d6405a0bb6ee43 Mon Sep 17 00:00:00 2001
> +From: Daniel Stenberg <[email protected]>
> +Date: Wed, 5 Aug 2026 10:02:53 +0200
> +Subject: [PATCH] http2: make server push transfers inherit share from parent
> +
> +Reported-by: Stephan Zeisberg
> +Closes #22488
> +
> +Upstream-Status: Backport 
> [https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43]
> +CVE: CVE-2026-18924
> +Signed-off-by: Siddharth Doshi <[email protected]>
> +---
> + lib/http2.c | 3 +++
> + 1 file changed, 3 insertions(+)
> +
> +diff --git a/lib/http2.c b/lib/http2.c
> +index 99d7f3b..e6305c9 100644
> +--- a/lib/http2.c
> ++++ b/lib/http2.c
> +@@ -47,6 +47,7 @@
> + #include "transfer.h"
> + #include "dynbuf.h"
> + #include "headers.h"
> ++#include "curl_share.h"
> + /* The last 3 #include files should be in this order */
> + #include "curl_printf.h"
> + #include "curl_memory.h"
> +@@ -776,6 +777,8 @@ static struct Curl_easy *h2_duphandle(struct 
> Curl_cfilter *cf,
> +       second->req.p.http = http;
> +       http2_data_setup(cf, second, &second_stream);
> +       second->state.priority.weight = data->state.priority.weight;
> ++      if(data->share)
> ++        (void)Curl_share_easy_link(second, data->share);
> +     }
> +   }
> +   return second;
> +--
> +2.34.1
> +
> diff --git a/meta/recipes-support/curl/curl_8.7.1.bb 
> b/meta/recipes-support/curl/curl_8.7.1.bb
> index 3f44cf02d31..905d0b47335 100644
> --- a/meta/recipes-support/curl/curl_8.7.1.bb
> +++ b/meta/recipes-support/curl/curl_8.7.1.bb
> @@ -42,6 +42,7 @@ SRC_URI = " \
>      file://CVE-2026-6253.patch \
>      file://CVE-2026-4873.patch \
>      file://CVE-2026-13608.patch \
> +    file://CVE-2026-18924.patch \
>  "
>
>  SRC_URI:append:class-nativesdk = " \
>
> 
>
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246530): 
https://lists.openembedded.org/g/openembedded-core/message/246530
Mute This Topic: https://lists.openembedded.org/mt/121389781/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to