VDB
RHSA-2026%3A10081
RHSA-2026%3A10081
PUBLISHED
CVSS 7.5 HIGH
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhcos-s390x-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19 | rhcos-s390x-4.19.9.6.202604211219-0, 4.19.9.6.202604211219-0 |
| Red Hat | rhcos-ppc64le-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19 | *, 4.19.9.6.202604211219-0 |
| Red Hat | rhcos-aarch64-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19 | *, 4.19.9.6.202604211219-0 |
| Red Hat | rhcos-x86_64-4.19.9.6.202604211219-0 as a component of Red Hat OpenShift Container Platform 4.19 | rhcos-x86_64-4.19.9.6.202604211219-0, 4.19.9.6.202604211219-0 |
Timeline
- Apr 29, 2026 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:10081 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2446453 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_10081.json advisory
- https://access.redhat.com/security/cve/CVE-2026-4111 advisory
- https://www.cve.org/CVERecord?id=CVE-2026-4111 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-4111 advisory
- https://github.com/libarchive/libarchive/pull/2877 advisory