CVE-2026-4111: Red Hat Ai Inference Server 3.2

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.

Affected products

  • Red Hat Red Hat Ai Inference Server 3.2: before 1780681984 (fixed in 1780681984); before 1775740563 (fixed in 1775740563)
  • Red Hat Red Hat Ai Inference Server 3.3: before 1778244559 (fixed in 1778244559); before 1778244531 (fixed in 1778244531); before 1778244546 (fixed in 1778244546); before 1775680192 (fixed in 1775680192); before 1775680262 (fixed in 1775680262); before 1775749857 (fixed in 1775749857)
  • Red Hat Red Hat Discovery 2: before 1775668717 (fixed in 1775668717); before 1775675922 (fixed in 1775675922)
  • Red Hat Red Hat Enterprise Linux 10: before 0:3.7.7-5.el10_1 (fixed in 0:3.7.7-5.el10_1)
  • Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:3.7.7-5.el10_0 (fixed in 0:3.7.7-5.el10_0)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 0:3.5.3-7.el9_7 (fixed in 0:3.5.3-7.el9_7)
  • Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:3.5.3-2.el9_0.3 (fixed in 0:3.5.3-2.el9_0.3)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:3.5.3-5.el9_2.1 (fixed in 0:3.5.3-5.el9_2.1)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:3.5.3-4.el9_4.2 (fixed in 0:3.5.3-4.el9_4.2)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:3.5.3-6.el9_6.1 (fixed in 0:3.5.3-6.el9_6.1)
  • Red Hat Red Hat Hardened Images: before 3.8.7-1.hum1 (fixed in 3.8.7-1.hum1)
  • Red Hat Red Hat Insights Proxy 1.5: before 1776868961 (fixed in 1776868961)
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Container Platform 4.13: before 413.92.202604080111-0 (fixed in 413.92.202604080111-0)
  • Red Hat Red Hat Openshift Container Platform 4.14: before 414.92.202605060243-0 (fixed in 414.92.202605060243-0)
  • Red Hat Red Hat Openshift Container Platform 4.15: before 415.92.202605060220-0 (fixed in 415.92.202605060220-0)
  • Red Hat Red Hat Openshift Container Platform 4.16: before 416.94.202604211449-0 (fixed in 416.94.202604211449-0)
  • Red Hat Red Hat Openshift Container Platform 4.17: before 417.94.202605112123-0 (fixed in 417.94.202605112123-0)
  • Red Hat Red Hat Openshift Container Platform 4.18: before 418.94.202604140044-0 (fixed in 418.94.202604140044-0)
  • Red Hat Red Hat Openshift Container Platform 4.19: before 4.19.9.6.202604211219-0 (fixed in 4.19.9.6.202604211219-0)
  • Red Hat Red Hat Update Infrastructure 5: before 1776868774 (fixed in 1776868774); before 1776868744 (fixed in 1776868744); before 1776868772 (fixed in 1776868772); before 1776868842 (fixed in 1776868842)

Published 2026-03-13. Last modified 2026-09-01.