Infinite loop in libarchive - CVE-2026-4111
Published: March 17, 2026
Vulnerability identifier: #VU124068
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L]
CVE-ID: CVE-2026-4111
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in the RAR5 decompression implementation. A remote attacker can pass specially crafted compressed data to the application, consume all available system resources and cause denial of service conditions.
Affected software
libarchive
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Service Interconnect
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libarchive (Ubuntu package)
libarchive (Red Hat package)
libarchive-devel
libarchive
bsdtar
bsdcpio
bsdunzip
libarchive-debuginfo
bsdcat
libarchive-debugsource
libarchive-help
libarchive-doc
Red Hat OpenShift Container Platform
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Service Interconnect
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libarchive (Ubuntu package)
libarchive (Red Hat package)
libarchive-devel
libarchive
bsdtar
bsdcpio
bsdunzip
libarchive-debuginfo
bsdcat
libarchive-debugsource
libarchive-help
libarchive-doc
Red Hat OpenShift Container Platform
How to mitigate CVE-2026-4111
Install updates from vendor's website.
libarchive - update to 3.8.6
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
Service Interconnect - update to 1
libarchive (Ubuntu package) - addressed in versions 3.1.2-7ubuntu2.8+esm4, 3.1.2-11ubuntu0.16.04.8+esm2, 3.2.2-3.1ubuntu0.7+esm2, 3.4.0-2ubuntu1.5+esm1, 3.6.0-1ubuntu1.6, 3.7.2-2ubuntu0.6, 3.7.7-0ubuntu3.1
libarchive (Red Hat package) - addressed in versions 3.5.3-2.el9_0.3, 3.5.3-4.el9_4.2, 3.5.3-5.el9_2.1, 3.5.3-6.el9_6.1, 3.5.3-7.el9_7, 3.7.7-5.el10_1
libarchive-devel - addressed in versions 3.5.3-7, 3.7.1-10
libarchive - addressed in versions 3.5.3-7, 3.7.1-10
bsdtar - addressed in versions 3.5.3-7, 3.7.1-10
libarchive-devel - update to 3.7.1-10
bsdcpio - update to 3.7.1-10
bsdtar - update to 3.7.1-10
bsdunzip - update to 3.7.1-10
libarchive-debuginfo - update to 3.7.1-10
bsdcat - update to 3.7.1-10
libarchive-debugsource - update to 3.7.1-10
libarchive-help - update to 3.7.1-10
bsdcat - update to 3.7.1-10
bsdcpio - update to 3.7.1-10
libarchive - update to 3.7.1-10
libarchive-doc - update to 3.7.1-10
bsdunzip - update to 3.7.1-10
libarchive - update to 3.8.6-1.fc44
Red Hat OpenShift Container Platform - addressed in versions 4.13.65, 4.18.38, 4.19.29
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
Service Interconnect - update to 1
libarchive (Ubuntu package) - addressed in versions 3.1.2-7ubuntu2.8+esm4, 3.1.2-11ubuntu0.16.04.8+esm2, 3.2.2-3.1ubuntu0.7+esm2, 3.4.0-2ubuntu1.5+esm1, 3.6.0-1ubuntu1.6, 3.7.2-2ubuntu0.6, 3.7.7-0ubuntu3.1
libarchive (Red Hat package) - addressed in versions 3.5.3-2.el9_0.3, 3.5.3-4.el9_4.2, 3.5.3-5.el9_2.1, 3.5.3-6.el9_6.1, 3.5.3-7.el9_7, 3.7.7-5.el10_1
libarchive-devel - addressed in versions 3.5.3-7, 3.7.1-10
libarchive - addressed in versions 3.5.3-7, 3.7.1-10
bsdtar - addressed in versions 3.5.3-7, 3.7.1-10
libarchive-devel - update to 3.7.1-10
bsdcpio - update to 3.7.1-10
bsdtar - update to 3.7.1-10
bsdunzip - update to 3.7.1-10
libarchive-debuginfo - update to 3.7.1-10
bsdcat - update to 3.7.1-10
libarchive-debugsource - update to 3.7.1-10
libarchive-help - update to 3.7.1-10
bsdcat - update to 3.7.1-10
bsdcpio - update to 3.7.1-10
libarchive - update to 3.7.1-10
libarchive-doc - update to 3.7.1-10
bsdunzip - update to 3.7.1-10
libarchive - update to 3.8.6-1.fc44
Red Hat OpenShift Container Platform - addressed in versions 4.13.65, 4.18.38, 4.19.29
External References
Related Security Bulletins
- Infinite loop in libarchive RAR5 implementation
- Red Hat Enterprise Linux 10 update for libarchive
- Red Hat Enterprise Linux 9 update for libarchive
- openEuler update for libarchive
- Anolis OS update for libarchive
- Fedora 44 update for libarchive
- Anolis OS update for libarchive
- Multiple vulnerabilities in Service Interconnect
- Red Hat Enterprise Linux 9 update for libarchive
- Ubuntu update for libarchive
- Red Hat Enterprise Linux 9 update for libarchive
- Red Hat Enterprise Linux 9 update for libarchive
- Red Hat Enterprise Linux 9 update for libarchive
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Infinite loop in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge