CVE-2026-4111 | Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.

Published: 2026-03-13 Last update: 2026-06-10 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2026-4111 is rated Low Risk (31.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.02%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2026-4111

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-21 0.06% 0.02% -0.04%
2 2026-03-19 0.04% 0.06% +0.02%
3 2026-03-13 0.04%

Full EPSS history (3 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2026-4111

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 3.6 [email protected]

Weakness enumeration for CVE-2026-4111

GitHub Security Advisory for CVE-2026-4111

GHSA-xrqh-48jh-pjv2 · Severity: high — A flaw was identified in the RAR5 archive decompression logic of the libarchive library,...

OS Trackers for CVE-2026-4111

vendor priority summary link
debian not yet assigned CVE-2026-4111 not yet assigned priority: Debian including 1 source packages (libarchive), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2026-4111
redhat high https://access.redhat.com/security/cve/CVE-2026-4111
suse high CVE-2026-4111 severity important: SUSE including 10 source package names (bsdtar-3.5.3-7.el9_7, bsdtar-3.7.7-5.el10_1, …), 22 product×package rows across 9 product lines (SUSE Liberty Linux 10, SUSE Liberty Linux 9, … (9 product lines)): Known Not Affected 16, Fixed 6. https://www.suse.com/security/cve/CVE-2026-4111/
ubuntu medium CVE-2026-4111 medium priority: Ubuntu including 1 source packages (libarchive), 8 status rows across 8 suites (bionic, focal, jammy, noble, questing, trusty, upstream, xenial): released 8. https://ubuntu.com/security/CVE-2026-4111

Affected software / configurations for CVE-2026-4111

Vendor Product Version Raw CPE
No affected products in dataset.

References for CVE-2026-4111

URL Tags
https://access.redhat.com/errata/RHSA-2026:10065
https://access.redhat.com/errata/RHSA-2026:10081
https://access.redhat.com/errata/RHSA-2026:10097
https://access.redhat.com/errata/RHSA-2026:14773
https://access.redhat.com/errata/RHSA-2026:15087
https://access.redhat.com/errata/RHSA-2026:16008
https://access.redhat.com/errata/RHSA-2026:16009
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:17596
https://access.redhat.com/errata/RHSA-2026:25096
https://access.redhat.com/errata/RHSA-2026:5063
https://access.redhat.com/errata/RHSA-2026:5080
https://access.redhat.com/errata/RHSA-2026:6647
https://access.redhat.com/errata/RHSA-2026:7093
https://access.redhat.com/errata/RHSA-2026:7105
https://access.redhat.com/errata/RHSA-2026:7106
https://access.redhat.com/errata/RHSA-2026:7239
https://access.redhat.com/errata/RHSA-2026:7329
https://access.redhat.com/errata/RHSA-2026:7335
https://access.redhat.com/errata/RHSA-2026:8423
https://access.redhat.com/errata/RHSA-2026:8746
https://access.redhat.com/errata/RHSA-2026:8747
https://access.redhat.com/errata/RHSA-2026:8748
https://access.redhat.com/errata/RHSA-2026:8865
https://access.redhat.com/errata/RHSA-2026:8944
https://access.redhat.com/errata/RHSA-2026:9832
https://access.redhat.com/security/cve/CVE-2026-4111
https://bugzilla.redhat.com/show_bug.cgi?id=2446453
https://github.com/libarchive/libarchive/pull/2877
cvelogic Threat Intelligence