Bug 2537756 (CVE-2026-95516) - CVE-2026-95516 zbar: zbar: heap-buffer-overflow write in Structured-Append QR text extraction
Summary: CVE-2026-95516 zbar: zbar: heap-buffer-overflow write in Structured-Append QR...
Keywords:
Status: NEW
Alias: CVE-2026-95516
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2537780 2537781
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 08:25 UTC by OSIDB Bzimport
Modified: 2026-09-22 08:57 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 08:25:13 UTC
A heap-buffer-overflow (OOB write of 1 byte) exists in the qr_code_data_list_extract_text() function in zbar/qrcode/qrdectxt.c. When decoding a Structured-Append (multi-symbol) QR group where some symbols are missing, the function writes NUL separator bytes (line 237) between present segments that were not accounted for in the buffer size calculation at line 196. The buffer is allocated as malloc(sa_ctext + 1), where sa_ctext counts only the payload data from present symbols and the +1 accounts for the final NUL terminator. However, each gap transition (missing-to-present segment boundary) writes an additional NUL byte that was never counted, causing a 1-byte heap overflow per gap. The simplest trigger is a single QR code declaring itself part of a 2-symbol SA group: the missing symbol creates one gap, resulting in exactly 1 byte overflow. The function is reachable from the public zbar_scan_image() API in a default build. The bytebuf_text allocation at line 219 uses the same undersized calculation but is not practically exploitable because it only holds raw byte data (at most sa_ctext/4 bytes due to the 4x expansion factor in the size estimate). Version 0.23.93 and the current master branch are affected; the code in qrdectxt.c has been unchanged since at least 2023. No upstream fix is available yet. Reporter: Calif.io, in collaboration with Anthropic. Reporter reference: ANT-2026-KY0E5WN8. PSIRT ticket: PSIRTSUPT-24186.


Note You need to log in before you can comment on or make changes to this bug.