CVE-2026-4111 Details
Description
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | redhat-SADP |
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
31 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | redhat-SADP |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 10, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 14, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Modified | [email protected] |
| May 12, 2026 | CVE Modified | [email protected] |
| Apr 30, 2026 | CVE Modified | [email protected] |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 25, 2026 | CVE Modified | [email protected] |
| Apr 23, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | CVE Modified | [email protected] |
| Apr 20, 2026 | CVE Modified | [email protected] |
| Apr 17, 2026 | CVE Modified | [email protected] |
| Apr 17, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | CVE Modified | [email protected] |
| Apr 9, 2026 | CVE Modified | [email protected] |
| Apr 9, 2026 | CVE Modified | [email protected] |
| Apr 8, 2026 | CVE Modified | [email protected] |
| Apr 8, 2026 | CVE Modified | [email protected] |
| Apr 6, 2026 | CVE Modified | [email protected] |
| Mar 19, 2026 | CVE Modified | [email protected] |
| Mar 19, 2026 | CVE Modified | [email protected] |
| Mar 13, 2026 | New CVE Received | [email protected] |