Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:7093 - Security Advisory
Issued:
2026-04-08
Updated:
2026-04-08

RHSA-2026:7093 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libarchive security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libarchive is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.

Security Fix(es):

  • libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive (CVE-2026-4111)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2446453 - CVE-2026-4111 libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive

CVEs

  • CVE-2026-4111

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
libarchive-3.5.3-2.el9_0.3.src.rpm SHA-256: 9d89cb9934830328df03153b853be74f55b08538fe1b8292878eb18b21a0a336
ppc64le
bsdcat-debuginfo-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: e9071d7781e3458fc648a7d0438a8e50bf7f56aaefef7efdd356c73e8b403143
bsdcat-debuginfo-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: e9071d7781e3458fc648a7d0438a8e50bf7f56aaefef7efdd356c73e8b403143
bsdcpio-debuginfo-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: 218fd442676246b74023032540c50dd158763e63d956c068288fa0f500d95def
bsdcpio-debuginfo-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: 218fd442676246b74023032540c50dd158763e63d956c068288fa0f500d95def
bsdtar-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: e1ec84a7b6afa8d01e523db231dd5214c87d93f6d226967a8d4817476f6aea38
bsdtar-debuginfo-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: fe94551d9d5094e799d5da33d9fb6abe06e9ee82e5352bc6307a20ed90a49173
bsdtar-debuginfo-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: fe94551d9d5094e799d5da33d9fb6abe06e9ee82e5352bc6307a20ed90a49173
libarchive-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: a6225c349f365564436f90a1eda5ce0c2eec01cdabac9d292f731dbc0d8bee48
libarchive-debuginfo-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: 822496d0edaade3b058c9ecd564dad422952b96b6d981a4d337833e48fe1d1f1
libarchive-debuginfo-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: 822496d0edaade3b058c9ecd564dad422952b96b6d981a4d337833e48fe1d1f1
libarchive-debugsource-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: 1df500fe3158a37d0fbeb90cc6a812db7db4d21a573865cf3505e6a9bff3747d
libarchive-debugsource-3.5.3-2.el9_0.3.ppc64le.rpm SHA-256: 1df500fe3158a37d0fbeb90cc6a812db7db4d21a573865cf3505e6a9bff3747d

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
libarchive-3.5.3-2.el9_0.3.src.rpm SHA-256: 9d89cb9934830328df03153b853be74f55b08538fe1b8292878eb18b21a0a336
x86_64
bsdcat-debuginfo-3.5.3-2.el9_0.3.i686.rpm SHA-256: db913eb114fd06e5a5fb829ec45c639a2701eb1b766dfb6ca4c2879bdf02e9d3
bsdcat-debuginfo-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 31fa19a865c986ef01ee6e7972361c0745bc207e0dccbceb55afdbb52610a2de
bsdcat-debuginfo-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 31fa19a865c986ef01ee6e7972361c0745bc207e0dccbceb55afdbb52610a2de
bsdcpio-debuginfo-3.5.3-2.el9_0.3.i686.rpm SHA-256: 9ffe5733d30f23daa9ae29863dfd47ca7b4e045b567b437b7691280824774800
bsdcpio-debuginfo-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 394a5bcf6793945175e5533d9a6e6275b5dbcf76889d1b5e8320d06c127639a8
bsdcpio-debuginfo-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 394a5bcf6793945175e5533d9a6e6275b5dbcf76889d1b5e8320d06c127639a8
bsdtar-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 22400699b57a8bf8dc45edb4ecedfc918de2b66b937e39ee94188bf63a330dfc
bsdtar-debuginfo-3.5.3-2.el9_0.3.i686.rpm SHA-256: 870d72e4dd3306bdf4c0af434e68fb03041e67b380becc9ef11d852bb4c62947
bsdtar-debuginfo-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 8ccee54ece19bece0a42b492df0bcdf192177f16fd3adad4fbd7a42a22ee7be9
bsdtar-debuginfo-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 8ccee54ece19bece0a42b492df0bcdf192177f16fd3adad4fbd7a42a22ee7be9
libarchive-3.5.3-2.el9_0.3.i686.rpm SHA-256: 43d17ac8d624fd875b6f3abe8ae13cf106aca6b76aa809fc6761fd16e9bcc49f
libarchive-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: f100f3229d3695a34dad36d48c6faf88f86e78d49a44d8a1d8b0cd0b9d1b65e8
libarchive-debuginfo-3.5.3-2.el9_0.3.i686.rpm SHA-256: 633c5c2c21fef2f6d894a83493b18c39560f9e6cba5919b3f43ce2e9188b4413
libarchive-debuginfo-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 9f9406d63edcb52c8ff59c40a909784fcab945f48aa941f78eaf0ee2e6905735
libarchive-debuginfo-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 9f9406d63edcb52c8ff59c40a909784fcab945f48aa941f78eaf0ee2e6905735
libarchive-debugsource-3.5.3-2.el9_0.3.i686.rpm SHA-256: aa7ee71e831e79a46db02d09f7fd110ea5aa5c3c8a36113c32b13bb2652a025e
libarchive-debugsource-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 08914a23b08578eaf3a9c65bb5a5c4c30d2c9868328ffa37d3aa4d2f4635cc86
libarchive-debugsource-3.5.3-2.el9_0.3.x86_64.rpm SHA-256: 08914a23b08578eaf3a9c65bb5a5c4c30d2c9868328ffa37d3aa4d2f4635cc86

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
libarchive-3.5.3-2.el9_0.3.src.rpm SHA-256: 9d89cb9934830328df03153b853be74f55b08538fe1b8292878eb18b21a0a336
aarch64
bsdcat-debuginfo-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: 519edb741c0558ed9d048a4c118d996c0bad2f21a23d61f003f454e8f41adef0
bsdcat-debuginfo-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: 519edb741c0558ed9d048a4c118d996c0bad2f21a23d61f003f454e8f41adef0
bsdcpio-debuginfo-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: 3e6039ae4bb51abda3e2fcc41f26ca14aeef25d3f05e39bab7452d86ab199155
bsdcpio-debuginfo-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: 3e6039ae4bb51abda3e2fcc41f26ca14aeef25d3f05e39bab7452d86ab199155
bsdtar-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: f8b6964ad79148034252cc1752169a8c8e5c7c953fbea0aa65372c36b0c74aa2
bsdtar-debuginfo-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: b3a08e059e0f7472360cffe143b9257aa9d91969a2fccfc84e1040879ef7fc7e
bsdtar-debuginfo-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: b3a08e059e0f7472360cffe143b9257aa9d91969a2fccfc84e1040879ef7fc7e
libarchive-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: a091e6478ac90ad1845f99c2a8cd48074181a1d82cb1e522cbf56d02a6a35d96
libarchive-debuginfo-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: 23fd76096d94adc70638d277634c5f14b0430ea80cb113da95a55952ea093a3b
libarchive-debuginfo-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: 23fd76096d94adc70638d277634c5f14b0430ea80cb113da95a55952ea093a3b
libarchive-debugsource-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: 6114130fd89cc1697f06740eaecadde8a25fa8add6c3c3920ddd030861d01363
libarchive-debugsource-3.5.3-2.el9_0.3.aarch64.rpm SHA-256: 6114130fd89cc1697f06740eaecadde8a25fa8add6c3c3920ddd030861d01363

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
libarchive-3.5.3-2.el9_0.3.src.rpm SHA-256: 9d89cb9934830328df03153b853be74f55b08538fe1b8292878eb18b21a0a336
s390x
bsdcat-debuginfo-3.5.3-2.el9_0.3.s390x.rpm SHA-256: e1429331974cb01167fa4ae82f691493bc5a3bd7fe9aa4aee5e495065c05e4c5
bsdcat-debuginfo-3.5.3-2.el9_0.3.s390x.rpm SHA-256: e1429331974cb01167fa4ae82f691493bc5a3bd7fe9aa4aee5e495065c05e4c5
bsdcpio-debuginfo-3.5.3-2.el9_0.3.s390x.rpm SHA-256: d03469178a38f83822a4554aea9a07aa7f3149daa93ca77524368d641e9c4fc6
bsdcpio-debuginfo-3.5.3-2.el9_0.3.s390x.rpm SHA-256: d03469178a38f83822a4554aea9a07aa7f3149daa93ca77524368d641e9c4fc6
bsdtar-3.5.3-2.el9_0.3.s390x.rpm SHA-256: 2ab9a60722b01923a3a1be59484d52e400ea6ee28d6c628148850975c7674248
bsdtar-debuginfo-3.5.3-2.el9_0.3.s390x.rpm SHA-256: f00c8e86377e7e390763328768260b2a6280ac8e0110686e69f0d590519a15dc
bsdtar-debuginfo-3.5.3-2.el9_0.3.s390x.rpm SHA-256: f00c8e86377e7e390763328768260b2a6280ac8e0110686e69f0d590519a15dc
libarchive-3.5.3-2.el9_0.3.s390x.rpm SHA-256: 0fd767c6b510e85ef841a0cbbe0251ca0ae967550d33ee353ec0f849b9c49a66
libarchive-debuginfo-3.5.3-2.el9_0.3.s390x.rpm SHA-256: 16a0f596af611a128d2e7a46411fa2ed9aebbe775d5ea18e1ff70b3c93c00dab
libarchive-debuginfo-3.5.3-2.el9_0.3.s390x.rpm SHA-256: 16a0f596af611a128d2e7a46411fa2ed9aebbe775d5ea18e1ff70b3c93c00dab
libarchive-debugsource-3.5.3-2.el9_0.3.s390x.rpm SHA-256: 84687bc53068e8387eaf6a220f92d03aba2382903fadd3f3e5da59c8da5a8d13
libarchive-debugsource-3.5.3-2.el9_0.3.s390x.rpm SHA-256: 84687bc53068e8387eaf6a220f92d03aba2382903fadd3f3e5da59c8da5a8d13

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility