On Wed Sep 23, 2026 at 5:22 PM CEST, Martin Jansa wrote:
> This breaks the build when nthttp2 PACKAGECONFIG is enabled, because
> curl_share.h included here was renamed from share.h in newer curl
> 8.22:
> https://github.com/curl/curl/commit/3887069c661b40e76b053a4867eb565d4761ab3e
> 8.7.1 version in scarthgap fails with:
> curl-8.7.1/lib/http2.c:50:10: fatal error: 'curl_share.h' file not found
>
> Using share.h instead of curl_share.h fixes the include, but then it fails 
> with
> curl-8.7.1/lib/http2.c:781:15: error: call to undeclared function
> 'Curl_share_easy_link'; ISO C99 and later do not support implicit
> function declarations [-Wimplicit-function-declaration]
>
> Curl_share_easy_link was added in 8.20 with:
> https://github.com/curl/curl/commit/82009c4220774417c821496affa4aa834c028b68
> and that will be a bit more difficult to backport.
>
> Please drop this one from the PR until it's resolved.
>
> Cheers,
>
> On Wed, Sep 23, 2026 at 11:12 AM Yoann Congal via
> lists.openembedded.org <[email protected]>
> wrote:
>>
>> From: Siddharth Doshi <[email protected]>
>>
>> Picking patch as per [1], and same patch is mentioned in [2]
>>
>> [1] https://curl.se/docs/CVE-2026-18924.html
>> [2] https://security-tracker.debian.org/tracker/CVE-2026-18924
>>
>> Signed-off-by: Siddharth Doshi <[email protected]>
>> Signed-off-by: Yoann Congal <[email protected]>
>> ---
>>  .../curl/curl/CVE-2026-18924.patch            | 39 +++++++++++++++++++
>>  meta/recipes-support/curl/curl_8.7.1.bb       |  1 +
>>  2 files changed, 40 insertions(+)
>>  create mode 100644 meta/recipes-support/curl/curl/CVE-2026-18924.patch
>>
>> diff --git a/meta/recipes-support/curl/curl/CVE-2026-18924.patch 
>> b/meta/recipes-support/curl/curl/CVE-2026-18924.patch
>> new file mode 100644
>> index 00000000000..28934ababee
>> --- /dev/null
>> +++ b/meta/recipes-support/curl/curl/CVE-2026-18924.patch
>> @@ -0,0 +1,39 @@
>> +From 90325ff0444cbdff368bda5d26d6405a0bb6ee43 Mon Sep 17 00:00:00 2001
>> +From: Daniel Stenberg <[email protected]>
>> +Date: Wed, 5 Aug 2026 10:02:53 +0200
>> +Subject: [PATCH] http2: make server push transfers inherit share from parent
>> +
>> +Reported-by: Stephan Zeisberg
>> +Closes #22488
>> +
>> +Upstream-Status: Backport 
>> [https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43]
>> +CVE: CVE-2026-18924
>> +Signed-off-by: Siddharth Doshi <[email protected]>
>> +---
>> + lib/http2.c | 3 +++
>> + 1 file changed, 3 insertions(+)
>> +
>> +diff --git a/lib/http2.c b/lib/http2.c
>> +index 99d7f3b..e6305c9 100644
>> +--- a/lib/http2.c
>> ++++ b/lib/http2.c
>> +@@ -47,6 +47,7 @@
>> + #include "transfer.h"
>> + #include "dynbuf.h"
>> + #include "headers.h"
>> ++#include "curl_share.h"
>> + /* The last 3 #include files should be in this order */
>> + #include "curl_printf.h"
>> + #include "curl_memory.h"

Ok, dropped. Nice catch.

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246571): 
https://lists.openembedded.org/g/openembedded-core/message/246571
Mute This Topic: https://lists.openembedded.org/mt/121389781/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to