Fedora Account System
Red Hat Associate
Red Hat Customer
A heap-buffer-overflow (OOB write of 1 byte) exists in the qr_code_data_list_extract_text() function in zbar/qrcode/qrdectxt.c. When decoding a Structured-Append (multi-symbol) QR group where some symbols are missing, the function writes NUL separator bytes (line 237) between present segments that were not accounted for in the buffer size calculation at line 196. The buffer is allocated as malloc(sa_ctext + 1), where sa_ctext counts only the payload data from present symbols and the +1 accounts for the final NUL terminator. However, each gap transition (missing-to-present segment boundary) writes an additional NUL byte that was never counted, causing a 1-byte heap overflow per gap. The simplest trigger is a single QR code declaring itself part of a 2-symbol SA group: the missing symbol creates one gap, resulting in exactly 1 byte overflow. The function is reachable from the public zbar_scan_image() API in a default build. The bytebuf_text allocation at line 219 uses the same undersized calculation but is not practically exploitable because it only holds raw byte data (at most sa_ctext/4 bytes due to the 4x expansion factor in the size estimate). Version 0.23.93 and the current master branch are affected; the code in qrdectxt.c has been unchanged since at least 2023. No upstream fix is available yet. Reporter: Calif.io, in collaboration with Anthropic. Reporter reference: ANT-2026-KY0E5WN8. PSIRT ticket: PSIRTSUPT-24186.