VDB

RHSA-2026%3A10081

RHSA-2026%3A10081 PUBLISHED CVSS 7.5 HIGH

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatrhcos-s390x-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19rhcos-s390x-4.19.9.6.202604211219-0, 4.19.9.6.202604211219-0
Red Hatrhcos-ppc64le-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19*, 4.19.9.6.202604211219-0
Red Hatrhcos-aarch64-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19*, 4.19.9.6.202604211219-0
Red Hatrhcos-x86_64-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19rhcos-x86_64-4.19.9.6.202604211219-0, 4.19.9.6.202604211219-0

Timeline

  • Apr 29, 2026 CVE Published
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
  • May 1, 2026 Security Advisory
  • May 14, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›