This breaks the build when nthttp2 PACKAGECONFIG is enabled, because curl_share.h included here was renamed from share.h in newer curl 8.22: https://github.com/curl/curl/commit/3887069c661b40e76b053a4867eb565d4761ab3e 8.7.1 version in scarthgap fails with: curl-8.7.1/lib/http2.c:50:10: fatal error: 'curl_share.h' file not found
Using share.h instead of curl_share.h fixes the include, but then it fails with curl-8.7.1/lib/http2.c:781:15: error: call to undeclared function 'Curl_share_easy_link'; ISO C99 and later do not support implicit function declarations [-Wimplicit-function-declaration] Curl_share_easy_link was added in 8.20 with: https://github.com/curl/curl/commit/82009c4220774417c821496affa4aa834c028b68 and that will be a bit more difficult to backport. Please drop this one from the PR until it's resolved. Cheers, On Wed, Sep 23, 2026 at 11:12 AM Yoann Congal via lists.openembedded.org <[email protected]> wrote: > > From: Siddharth Doshi <[email protected]> > > Picking patch as per [1], and same patch is mentioned in [2] > > [1] https://curl.se/docs/CVE-2026-18924.html > [2] https://security-tracker.debian.org/tracker/CVE-2026-18924 > > Signed-off-by: Siddharth Doshi <[email protected]> > Signed-off-by: Yoann Congal <[email protected]> > --- > .../curl/curl/CVE-2026-18924.patch | 39 +++++++++++++++++++ > meta/recipes-support/curl/curl_8.7.1.bb | 1 + > 2 files changed, 40 insertions(+) > create mode 100644 meta/recipes-support/curl/curl/CVE-2026-18924.patch > > diff --git a/meta/recipes-support/curl/curl/CVE-2026-18924.patch > b/meta/recipes-support/curl/curl/CVE-2026-18924.patch > new file mode 100644 > index 00000000000..28934ababee > --- /dev/null > +++ b/meta/recipes-support/curl/curl/CVE-2026-18924.patch > @@ -0,0 +1,39 @@ > +From 90325ff0444cbdff368bda5d26d6405a0bb6ee43 Mon Sep 17 00:00:00 2001 > +From: Daniel Stenberg <[email protected]> > +Date: Wed, 5 Aug 2026 10:02:53 +0200 > +Subject: [PATCH] http2: make server push transfers inherit share from parent > + > +Reported-by: Stephan Zeisberg > +Closes #22488 > + > +Upstream-Status: Backport > [https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43] > +CVE: CVE-2026-18924 > +Signed-off-by: Siddharth Doshi <[email protected]> > +--- > + lib/http2.c | 3 +++ > + 1 file changed, 3 insertions(+) > + > +diff --git a/lib/http2.c b/lib/http2.c > +index 99d7f3b..e6305c9 100644 > +--- a/lib/http2.c > ++++ b/lib/http2.c > +@@ -47,6 +47,7 @@ > + #include "transfer.h" > + #include "dynbuf.h" > + #include "headers.h" > ++#include "curl_share.h" > + /* The last 3 #include files should be in this order */ > + #include "curl_printf.h" > + #include "curl_memory.h" > +@@ -776,6 +777,8 @@ static struct Curl_easy *h2_duphandle(struct > Curl_cfilter *cf, > + second->req.p.http = http; > + http2_data_setup(cf, second, &second_stream); > + second->state.priority.weight = data->state.priority.weight; > ++ if(data->share) > ++ (void)Curl_share_easy_link(second, data->share); > + } > + } > + return second; > +-- > +2.34.1 > + > diff --git a/meta/recipes-support/curl/curl_8.7.1.bb > b/meta/recipes-support/curl/curl_8.7.1.bb > index 3f44cf02d31..905d0b47335 100644 > --- a/meta/recipes-support/curl/curl_8.7.1.bb > +++ b/meta/recipes-support/curl/curl_8.7.1.bb > @@ -42,6 +42,7 @@ SRC_URI = " \ > file://CVE-2026-6253.patch \ > file://CVE-2026-4873.patch \ > file://CVE-2026-13608.patch \ > + file://CVE-2026-18924.patch \ > " > > SRC_URI:append:class-nativesdk = " \ > > >
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#246530): https://lists.openembedded.org/g/openembedded-core/message/246530 Mute This Topic: https://lists.openembedded.org/mt/121389781/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
