Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5080 - Security Advisory
Issued:
2026-03-19
Updated:
2026-03-19

RHSA-2026:5080 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libarchive security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libarchive is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.

Security Fix(es):

  • libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive (CVE-2026-4111)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2446453 - CVE-2026-4111 libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive

CVEs

  • CVE-2026-4111

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
libarchive-3.5.3-7.el9_7.src.rpm SHA-256: f4e99305ad36a2998b3980f4912d9b77a05326a65c6e3e7aea0552d69857a9ee
x86_64
bsdcat-debuginfo-3.5.3-7.el9_7.i686.rpm SHA-256: dbe836e3f909ad945e7ebe0b98739552571561a3d56c51df17f8e207d3b0bb8b
bsdcat-debuginfo-3.5.3-7.el9_7.i686.rpm SHA-256: dbe836e3f909ad945e7ebe0b98739552571561a3d56c51df17f8e207d3b0bb8b
bsdcat-debuginfo-3.5.3-7.el9_7.x86_64.rpm SHA-256: 0f010b555020990b6bf291abffd89c1ce003ec278ec705b7c030e410bb5bd001
bsdcat-debuginfo-3.5.3-7.el9_7.x86_64.rpm SHA-256: 0f010b555020990b6bf291abffd89c1ce003ec278ec705b7c030e410bb5bd001
bsdcpio-debuginfo-3.5.3-7.el9_7.i686.rpm SHA-256: 07f20969cc46f0e7b6a50fdb77c49c7cb39c235f6916dc28e53ddf030e4946d5
bsdcpio-debuginfo-3.5.3-7.el9_7.i686.rpm SHA-256: 07f20969cc46f0e7b6a50fdb77c49c7cb39c235f6916dc28e53ddf030e4946d5
bsdcpio-debuginfo-3.5.3-7.el9_7.x86_64.rpm SHA-256: 83b377b50d187cef5ce389a8ef7a93a1fa85d76eeaa20a7b9dd5335f1539ce37
bsdcpio-debuginfo-3.5.3-7.el9_7.x86_64.rpm SHA-256: 83b377b50d187cef5ce389a8ef7a93a1fa85d76eeaa20a7b9dd5335f1539ce37
bsdtar-3.5.3-7.el9_7.x86_64.rpm SHA-256: 94cbc82e4a8a99f99bc0cc6d9bdf8d08f688a4591b2cdb07a59d0c33deaedf64
bsdtar-debuginfo-3.5.3-7.el9_7.i686.rpm SHA-256: 587ebd2f962900c01938bc042051d06fd351ef3994c58d7cbe493e32e766bf9d
bsdtar-debuginfo-3.5.3-7.el9_7.i686.rpm SHA-256: 587ebd2f962900c01938bc042051d06fd351ef3994c58d7cbe493e32e766bf9d
bsdtar-debuginfo-3.5.3-7.el9_7.x86_64.rpm SHA-256: 34e269e3140708929c8328c55f9b59531511383171266ba24904dad83a7e0457
bsdtar-debuginfo-3.5.3-7.el9_7.x86_64.rpm SHA-256: 34e269e3140708929c8328c55f9b59531511383171266ba24904dad83a7e0457
libarchive-3.5.3-7.el9_7.i686.rpm SHA-256: 0a0d9174d43a2b823217f1feaee413781ab74b76abfb67d79a096e9b85374040
libarchive-3.5.3-7.el9_7.x86_64.rpm SHA-256: 609bfa9ffb43ecd00be7c8bac56f98f4a1861651d3ca9cfbcec647bfb9dcf612
libarchive-debuginfo-3.5.3-7.el9_7.i686.rpm SHA-256: 4b63c036289a2e7c75994159c4a4c713a6840a982999f17150e5ea68b8408117
libarchive-debuginfo-3.5.3-7.el9_7.i686.rpm SHA-256: 4b63c036289a2e7c75994159c4a4c713a6840a982999f17150e5ea68b8408117
libarchive-debuginfo-3.5.3-7.el9_7.x86_64.rpm SHA-256: a73bb01d500a11a4847172cd9f8682166d8264334945594b884871a5d1b4a216
libarchive-debuginfo-3.5.3-7.el9_7.x86_64.rpm SHA-256: a73bb01d500a11a4847172cd9f8682166d8264334945594b884871a5d1b4a216
libarchive-debugsource-3.5.3-7.el9_7.i686.rpm SHA-256: bf5e91527e6c25f22a1b5e9d44ecab91aadfce85e0bb18f5ad40d35a6f3aefbc
libarchive-debugsource-3.5.3-7.el9_7.i686.rpm SHA-256: bf5e91527e6c25f22a1b5e9d44ecab91aadfce85e0bb18f5ad40d35a6f3aefbc
libarchive-debugsource-3.5.3-7.el9_7.x86_64.rpm SHA-256: cf28ef597c0d3ed01e6f8e0870187cf9cda241e54b8ccdf7ee2d003a39b469e8
libarchive-debugsource-3.5.3-7.el9_7.x86_64.rpm SHA-256: cf28ef597c0d3ed01e6f8e0870187cf9cda241e54b8ccdf7ee2d003a39b469e8
libarchive-devel-3.5.3-7.el9_7.i686.rpm SHA-256: fd846bc30d95b759233a779a3a2d699d34ff4eace48b762caa2173cf8efe086d
libarchive-devel-3.5.3-7.el9_7.x86_64.rpm SHA-256: 0914d22edb65cfee5e2f41cf59f388849671fba5b70c29032187b1b2ec51284a

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
libarchive-3.5.3-7.el9_7.src.rpm SHA-256: f4e99305ad36a2998b3980f4912d9b77a05326a65c6e3e7aea0552d69857a9ee
s390x
bsdcat-debuginfo-3.5.3-7.el9_7.s390x.rpm SHA-256: 4c85dae61e8b31e367192c395f459905afc303e9be53428c3a97f9a4c8e6aee7
bsdcat-debuginfo-3.5.3-7.el9_7.s390x.rpm SHA-256: 4c85dae61e8b31e367192c395f459905afc303e9be53428c3a97f9a4c8e6aee7
bsdcpio-debuginfo-3.5.3-7.el9_7.s390x.rpm SHA-256: 7edbd2353fff5b68fdb5f4692e818615a0c7462ca5f740ce80cda9e95a250d66
bsdcpio-debuginfo-3.5.3-7.el9_7.s390x.rpm SHA-256: 7edbd2353fff5b68fdb5f4692e818615a0c7462ca5f740ce80cda9e95a250d66
bsdtar-3.5.3-7.el9_7.s390x.rpm SHA-256: 33bac2464c11a611f406cfc9fb1280d18d0104b29755b44a32e59c645ca72fe2
bsdtar-debuginfo-3.5.3-7.el9_7.s390x.rpm SHA-256: e66e7c449a263bc435d71a55e001c749c2fcb149454e8b3c989af83abfd80681
bsdtar-debuginfo-3.5.3-7.el9_7.s390x.rpm SHA-256: e66e7c449a263bc435d71a55e001c749c2fcb149454e8b3c989af83abfd80681
libarchive-3.5.3-7.el9_7.s390x.rpm SHA-256: 963a6e96b9b946a85e13d290789c10c1535eb53b69f08289d988c5637bc0fd74
libarchive-debuginfo-3.5.3-7.el9_7.s390x.rpm SHA-256: d72308d31746a22dd843452046068a98497b1cd9fe789deab669e138ec6da376
libarchive-debuginfo-3.5.3-7.el9_7.s390x.rpm SHA-256: d72308d31746a22dd843452046068a98497b1cd9fe789deab669e138ec6da376
libarchive-debugsource-3.5.3-7.el9_7.s390x.rpm SHA-256: 094ff1c4030d59b0fbe994741f0555ab008c4bec56f15856204f7bc5a0823d00
libarchive-debugsource-3.5.3-7.el9_7.s390x.rpm SHA-256: 094ff1c4030d59b0fbe994741f0555ab008c4bec56f15856204f7bc5a0823d00
libarchive-devel-3.5.3-7.el9_7.s390x.rpm SHA-256: 9d2e86f46e1cab973f6e2aa5711235e599fd5de129e733be40c14a8b9780307c

Red Hat Enterprise Linux for Power, little endian 9

SRPM
libarchive-3.5.3-7.el9_7.src.rpm SHA-256: f4e99305ad36a2998b3980f4912d9b77a05326a65c6e3e7aea0552d69857a9ee
ppc64le
bsdcat-debuginfo-3.5.3-7.el9_7.ppc64le.rpm SHA-256: acaed3fb4d0a7629bd2dea7469c24e16924741b3f951d1ddc2ca64583a8d3d64
bsdcat-debuginfo-3.5.3-7.el9_7.ppc64le.rpm SHA-256: acaed3fb4d0a7629bd2dea7469c24e16924741b3f951d1ddc2ca64583a8d3d64
bsdcpio-debuginfo-3.5.3-7.el9_7.ppc64le.rpm SHA-256: 43772b8e28ebfec6494d32c4245586a9bb9e4ee357fb6a72f40b05f7023cde7d
bsdcpio-debuginfo-3.5.3-7.el9_7.ppc64le.rpm SHA-256: 43772b8e28ebfec6494d32c4245586a9bb9e4ee357fb6a72f40b05f7023cde7d
bsdtar-3.5.3-7.el9_7.ppc64le.rpm SHA-256: f2a0109c11d42319bb92d040dbef9d7cb3fe79a24de46b132e85c0d0b0405a61
bsdtar-debuginfo-3.5.3-7.el9_7.ppc64le.rpm SHA-256: 351dfcd2ae5f5d66e02b59f9cc734b95a04ee7c9cb0e4f959a3a2ecd7cfb3fbc
bsdtar-debuginfo-3.5.3-7.el9_7.ppc64le.rpm SHA-256: 351dfcd2ae5f5d66e02b59f9cc734b95a04ee7c9cb0e4f959a3a2ecd7cfb3fbc
libarchive-3.5.3-7.el9_7.ppc64le.rpm SHA-256: ee200934415d28fba97a870e74bc8445240edb6178bb2dd9f9ae45b1342aec5a
libarchive-debuginfo-3.5.3-7.el9_7.ppc64le.rpm SHA-256: 381e547721df73c590cce096a62f5b4934c6270740b0e3547ec639e98e866005
libarchive-debuginfo-3.5.3-7.el9_7.ppc64le.rpm SHA-256: 381e547721df73c590cce096a62f5b4934c6270740b0e3547ec639e98e866005
libarchive-debugsource-3.5.3-7.el9_7.ppc64le.rpm SHA-256: bae7c10d16d811db7bf1a75873a92c8bb762b4e07688416af800a0eace116a62
libarchive-debugsource-3.5.3-7.el9_7.ppc64le.rpm SHA-256: bae7c10d16d811db7bf1a75873a92c8bb762b4e07688416af800a0eace116a62
libarchive-devel-3.5.3-7.el9_7.ppc64le.rpm SHA-256: e3d2ee4fda58de598c80055140b74934ec15694898d48c380716fa39a31dc360

Red Hat Enterprise Linux for ARM 64 9

SRPM
libarchive-3.5.3-7.el9_7.src.rpm SHA-256: f4e99305ad36a2998b3980f4912d9b77a05326a65c6e3e7aea0552d69857a9ee
aarch64
bsdcat-debuginfo-3.5.3-7.el9_7.aarch64.rpm SHA-256: a1f4a7385e03ffaf9254ce83a8efd92478e501cde5224264f42328cbce15e973
bsdcat-debuginfo-3.5.3-7.el9_7.aarch64.rpm SHA-256: a1f4a7385e03ffaf9254ce83a8efd92478e501cde5224264f42328cbce15e973
bsdcpio-debuginfo-3.5.3-7.el9_7.aarch64.rpm SHA-256: 9ac775ae077de2f5cebe27ee07cd3959516102461cd6749bc0bf61c374162e89
bsdcpio-debuginfo-3.5.3-7.el9_7.aarch64.rpm SHA-256: 9ac775ae077de2f5cebe27ee07cd3959516102461cd6749bc0bf61c374162e89
bsdtar-3.5.3-7.el9_7.aarch64.rpm SHA-256: 3e61a202fb59a46ca7e6bc2dc3e35ec7a6a459b85148f6451f4b58982fd0cdba
bsdtar-debuginfo-3.5.3-7.el9_7.aarch64.rpm SHA-256: 34eb8b277b68b06b6336337058d9119263b0d9a901f891493ffa2436d78f653b
bsdtar-debuginfo-3.5.3-7.el9_7.aarch64.rpm SHA-256: 34eb8b277b68b06b6336337058d9119263b0d9a901f891493ffa2436d78f653b
libarchive-3.5.3-7.el9_7.aarch64.rpm SHA-256: 5b9508503bf6dcd57161bbde6d4da4eb4cf186a225c77de374436618076fce02
libarchive-debuginfo-3.5.3-7.el9_7.aarch64.rpm SHA-256: bcad5540a95dcb70c2cecaeb2cdfc4dcd4ff13f8b7945c7caca7d3929d46e5d5
libarchive-debuginfo-3.5.3-7.el9_7.aarch64.rpm SHA-256: bcad5540a95dcb70c2cecaeb2cdfc4dcd4ff13f8b7945c7caca7d3929d46e5d5
libarchive-debugsource-3.5.3-7.el9_7.aarch64.rpm SHA-256: 943195df17fe1651149d089a5b3e850d62b46000766350391f8faae8fac3dade
libarchive-debugsource-3.5.3-7.el9_7.aarch64.rpm SHA-256: 943195df17fe1651149d089a5b3e850d62b46000766350391f8faae8fac3dade
libarchive-devel-3.5.3-7.el9_7.aarch64.rpm SHA-256: 9b3d054998fe94d2f530fc685ab69c9dc52219db01a91930af31b12dcf0b9ace

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility