Logo
vulnerabilityCVE-2026-4111
Name
CVE-2026-4111
Source
NVD ( link)Debian ( link)
Description
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libarchive
Patched

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.8.7
Not Affected
buildroot
master
3.8.8
Not Affected
openwrt
master
3.8.1-r2
Not Affected
openwrt
openwrt-25.12
3.8.1-r2
Not Affected
yocto
master
3.8.7
Not Affected
yocto
scarthgap
3.7.9
Patched

Resolved with patches#


libarchive (yocto:kirkstone)

#
Title
Author
Resolve
1
Reject filters when the block length is nonsensical
Tim Kientzle <kientzle@acm.org>
CVE-2026-4111
2
Infinite loop in Rar5 decompression
Tim Kientzle <kientzle@acm.org>
CVE-2026-4111

libarchive (yocto:scarthgap)

#
Title
Author
Resolve
1
Reject filters when the block length is nonsensical
Tim Kientzle <kientzle@acm.org>
CVE-2026-4111
2
Infinite loop in Rar5 decompression
Tim Kientzle <kientzle@acm.org>
CVE-2026-4111