DEBIAN-CVE-2026-88371

Source
https://security-tracker.debian.org/tracker/CVE-2026-88371
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88371.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-88371
Upstream
  • CVE-2026-88371
Published
2026-09-24T16:17:14Z
Modified
2026-09-26T23:00:08Z
Summary
[none]
Details

ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing specially crafted Code 128 input, decode_e() can return -1 for an invalid edge pattern, and decode6() subsequently left-shifts this negative signed value while constructing the edge signature. The operation invokes undefined behavior and can terminate trap-mode UBSan builds with SIGILL, resulting in denial of service.

References

Affected packages

Debian:12 / zbar

Package

Name
zbar
Purl
pkg:deb/debian/zbar?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.23.92-7
0.23.92-7+deb12u1
0.23.92-8
0.23.92-9
0.23.93-1
0.23.93-1.1~exp1
0.23.93-1.1
0.23.93-2
0.23.93-3
0.23.93-4
0.23.93-5
0.23.93-6
0.23.93-7
0.23.93-8
0.23.93-9
0.23.93-10

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88371.json"

Debian:13 / zbar

Package

Name
zbar
Purl
pkg:deb/debian/zbar?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.23.93-8
0.23.93-9
0.23.93-10

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88371.json"

Debian:14 / zbar

Package

Name
zbar
Purl
pkg:deb/debian/zbar?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.23.93-8
0.23.93-9
0.23.93-10

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88371.json"