VDB
RHSA-2026%3A10081
RHSA-2026%3A10081
PUBLISHED
CVSS 7.5 HIGH
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhcos-s390x-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19 | rhcos-s390x-4.19.9.6.202604211219-0, 4.19.9.6.202604211219-0 |
| Red Hat | rhcos-ppc64le-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19 | *, 4.19.9.6.202604211219-0 |
| Red Hat | rhcos-aarch64-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19 | *, 4.19.9.6.202604211219-0 |
| Red Hat | rhcos-x86_64-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19 | rhcos-x86_64-4.19.9.6.202604211219-0, 4.19.9.6.202604211219-0 |
Timeline
- Apr 29, 2026 CVE Published
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
- May 15, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2446453 issue
- https://www.cve.org/CVERecord?id=CVE-2026-4111 advisory
- https://github.com/libarchive/libarchive/pull/2877 advisory
- https://access.redhat.com/errata/RHSA-2026:10081 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10081.json advisory
- https://access.redhat.com/security/cve/CVE-2026-4111 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-4111 advisory