Bug 2537756 (CVE-2026-95516)

Summary: CVE-2026-95516 zbar: zbar: heap-buffer-overflow write in Structured-Append QR text extraction
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the ZBar barcode reader library. A heap-buffer-overflow write of one byte occurs when processing Structured-Append QR codes where the buffer size calculation does not account for NUL separator bytes inserted between decoded segments. An attacker could exploit this by crafting a QR code image that, when scanned by an application using zbar, causes heap corruption leading to a denial of service (application crash).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2537780, 2537781    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-22 08:25:13 UTC
A heap-buffer-overflow (OOB write of 1 byte) exists in the qr_code_data_list_extract_text() function in zbar/qrcode/qrdectxt.c. When decoding a Structured-Append (multi-symbol) QR group where some symbols are missing, the function writes NUL separator bytes (line 237) between present segments that were not accounted for in the buffer size calculation at line 196. The buffer is allocated as malloc(sa_ctext + 1), where sa_ctext counts only the payload data from present symbols and the +1 accounts for the final NUL terminator. However, each gap transition (missing-to-present segment boundary) writes an additional NUL byte that was never counted, causing a 1-byte heap overflow per gap. The simplest trigger is a single QR code declaring itself part of a 2-symbol SA group: the missing symbol creates one gap, resulting in exactly 1 byte overflow. The function is reachable from the public zbar_scan_image() API in a default build. The bytebuf_text allocation at line 219 uses the same undersized calculation but is not practically exploitable because it only holds raw byte data (at most sa_ctext/4 bytes due to the 4x expansion factor in the size estimate). Version 0.23.93 and the current master branch are affected; the code in qrdectxt.c has been unchanged since at least 2023. No upstream fix is available yet. Reporter: Calif.io, in collaboration with Anthropic. Reporter reference: ANT-2026-KY0E5WN8. PSIRT ticket: PSIRTSUPT-24186.