Infinite loop in libarchive - CVE-2026-4111

 

Infinite loop in libarchive - CVE-2026-4111

Published: March 17, 2026


Vulnerability identifier: #VU124068
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L]
CVE-ID: CVE-2026-4111
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop in the RAR5 decompression implementation. A remote attacker can pass specially crafted compressed data to the application, consume all available system resources and cause denial of service conditions.


Affected software

libarchive
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Service Interconnect
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libarchive (Ubuntu package)
libarchive (Red Hat package)
libarchive-devel
libarchive
bsdtar
bsdcpio
bsdunzip
libarchive-debuginfo
bsdcat
libarchive-debugsource
libarchive-help
libarchive-doc
Red Hat OpenShift Container Platform

How to mitigate CVE-2026-4111

Install updates from vendor's website.

libarchive - update to 3.8.6
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
Service Interconnect - update to 1
libarchive (Ubuntu package) - addressed in versions 3.1.2-7ubuntu2.8+esm4, 3.1.2-11ubuntu0.16.04.8+esm2, 3.2.2-3.1ubuntu0.7+esm2, 3.4.0-2ubuntu1.5+esm1, 3.6.0-1ubuntu1.6, 3.7.2-2ubuntu0.6, 3.7.7-0ubuntu3.1
libarchive (Red Hat package) - addressed in versions 3.5.3-2.el9_0.3, 3.5.3-4.el9_4.2, 3.5.3-5.el9_2.1, 3.5.3-6.el9_6.1, 3.5.3-7.el9_7, 3.7.7-5.el10_1
libarchive-devel - addressed in versions 3.5.3-7, 3.7.1-10
libarchive - addressed in versions 3.5.3-7, 3.7.1-10
bsdtar - addressed in versions 3.5.3-7, 3.7.1-10
libarchive-devel - update to 3.7.1-10
bsdcpio - update to 3.7.1-10
bsdtar - update to 3.7.1-10
bsdunzip - update to 3.7.1-10
libarchive-debuginfo - update to 3.7.1-10
bsdcat - update to 3.7.1-10
libarchive-debugsource - update to 3.7.1-10
libarchive-help - update to 3.7.1-10
bsdcat - update to 3.7.1-10
bsdcpio - update to 3.7.1-10
libarchive - update to 3.7.1-10
libarchive-doc - update to 3.7.1-10
bsdunzip - update to 3.7.1-10
libarchive - update to 3.8.6-1.fc44
Red Hat OpenShift Container Platform - addressed in versions 4.13.65, 4.18.38, 4.19.29

External References

Related Security Bulletins