<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:57:17.678036+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:5063</id>
    <title>ALSA-2026:5063 — Important: libarchive security update</title>
    <updated>2026-10-02T14:57:17.719063+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: bsdtar, AlmaLinux:10: libarchive, AlmaLinux:10: libarchive-devel</p>
<p>The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.</p>
<p>Security Fix(es):</p>
<p>* libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive (CVE-2026-4111)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:5063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07260</id>
    <title>bdu:2026-07260</title>
    <updated>2026-10-02T14:57:17.719138+00:00</updated>
    <content>bdu:2026-07260</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07260"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-4111</id>
    <title>BELL-CVE-2026-4111</title>
    <updated>2026-10-02T14:57:17.719155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: libarchive, Alpaquita:25: libarchive, Alpaquita:stream: libarchive</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-4111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0321</id>
    <title>certfr-2026-avi-0321 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T14:57:17.719175+00:00</updated>
    <content>certfr-2026-avi-0321</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362259</id>
    <title>EUVD-2026-362259</title>
    <updated>2026-10-02T14:57:17.719190+00:00</updated>
    <content>EUVD-2026-362259</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362259"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-4111</id>
    <title>fkie_cve-2026-4111</title>
    <updated>2026-10-02T14:57:17.719200+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-4111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xrqh-48jh-pjv2</id>
    <title>GHSA-xrqh-48jh-pjv2</title>
    <updated>2026-10-02T14:57:17.719249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xrqh-48jh-pjv2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-4111</id>
    <title>msrc_CVE-2026-4111 — Libarchive: infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive</title>
    <updated>2026-10-02T14:57:17.719290+00:00</updated>
    <content>msrc_CVE-2026-4111</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-4111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1641</id>
    <title>OESA-2026-1641 — libarchive security update</title>
    <updated>2026-10-02T14:57:17.719319+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: libarchive, openEuler:20.03-LTS-SP4: libarchive, openEuler:22.03-LTS-SP4: libarchive, openEuler:24.03-LTS: libarchive, openEuler:24.03-LTS-SP1: libarchive, openEuler:24.03-LTS-SP2: libarchive</p>
<p>is an open-source BSD-licensed C programming library that  provides streaming access to a variety of different archive formats, including tar, cpio, pax, zip, and ISO9660 images. The distribution  also includes bsdtar and bsdcpio, full-featured implementations of  tar and cpio that use .

Security Fix(es):</p>
<p>A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.(CVE-2026-4111)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1641"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20797-1</id>
    <title>openSUSE-SU-2026:20797-1 — Security update for libarchive</title>
    <updated>2026-10-02T14:57:17.719354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libarchive</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20797-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10065</id>
    <title>RHSA-2026:10065 — Red Hat Security Advisory: Red Hat Update Infrastructure 5.1 security update</title>
    <updated>2026-10-02T14:57:17.719373+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libxslt: Processing web content may disclose sensitive information nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing python: Python: Command-line option injection in webbrowser.open() via crafted URLs libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing net/url: Incorrect parsing of IPv6 host literals in net/url vim: Vim: Arbitrary code execution via 'helpfile' option processing nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination NGINX: NGINX: Denial of Service via undisclosed requests when ngx_mail_auth_http_module is enabled NGINX: NGINX: Denial of Service or file modification via buffer overflow in ngx_http_dav_module NGINX: NGINX: Denial of Service due to memory corruption via crafted MP4 file vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin vim: Vim: Denial of service and information disclosure via crafted swap file nginx: NGINX: Denial of Service or Code Execution via specially crafted MP4 files vim: Vim: Arbitrary code execution via command injection in glob() function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10065"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21757-1</id>
    <title>SUSE-SU-2026:21757-1 — Security update for libarchive</title>
    <updated>2026-10-02T14:57:17.719415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libarchive</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21757-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4111</id>
    <title>UBUNTU-CVE-2026-4111</title>
    <updated>2026-10-02T14:57:17.719431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libarchive, Ubuntu:Pro:16.04:LTS: libarchive, Ubuntu:Pro:18.04:LTS: libarchive, Ubuntu:Pro:20.04:LTS: libarchive, Ubuntu:22.04:LTS: libarchive, Ubuntu:24.04:LTS: libarchive, Ubuntu:25.10: libarchive</p>
<p>A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-4111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0785</id>
    <title>WID-SEC-W-2026-0785 — libarchive: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T14:57:17.719459+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libarchive ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0785"/>
  </entry>
</feed>
