<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
	<DocumentTitle xml:lang="en">An update for libarchive is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP2</DocumentTitle>
	<DocumentType>Security Advisory</DocumentType>
	<DocumentPublisher Type="Vendor">
		<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
		<IssuingAuthority>openEuler security committee</IssuingAuthority>
	</DocumentPublisher>
	<DocumentTracking>
		<Identification>
			<ID>openEuler-SA-2026-1641</ID>
		</Identification>
		<Status>Final</Status>
		<Version>1.0</Version>
		<RevisionHistory>
			<Revision>
				<Number>1.0</Number>
				<Date>2026-03-20</Date>
				<Description>Initial</Description>
			</Revision>
		</RevisionHistory>
		<InitialReleaseDate>2026-03-20</InitialReleaseDate>
		<CurrentReleaseDate>2026-03-20</CurrentReleaseDate>
		<Generator>
			<Engine>openEuler SA Tool V1.0</Engine>
			<Date>2026-03-20</Date>
		</Generator>
	</DocumentTracking>
	<DocumentNotes>
		<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">libarchive security update</Note>
		<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for libarchive is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP2</Note>
		<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">is an open-source BSD-licensed C programming library that  provides streaming access to a variety of different archive formats, including tar, cpio, pax, zip, and ISO9660 images. The distribution  also includes bsdtar and bsdcpio, full-featured implementations of  tar and cpio that use .

Security Fix(es):

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.(CVE-2026-4111)</Note>
		<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for libarchive is now available for openEuler-24.03-LTS-SP3,openEuler-20.03-LTS-SP4,openEuler-22.03-LTS-SP4,openEuler-24.03-LTS,openEuler-24.03-LTS-SP1,openEuler-24.03-LTS-SP2.

openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
		<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">High</Note>
		<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">libarchive</Note>
	</DocumentNotes>
	<DocumentReferences>
		<Reference Type="Self">
			<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1641</URL>
		</Reference>
		<Reference Type="openEuler CVE">
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-4111</URL>
		</Reference>
		<Reference Type="Other">
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-4111</URL>
		</Reference>
	</DocumentReferences>
	<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
		<Branch Type="Product Name" Name="openEuler">
			<FullProductName ProductID="openEuler-24.03-LTS-SP3" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">openEuler-24.03-LTS-SP3</FullProductName>
			<FullProductName ProductID="openEuler-20.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">openEuler-20.03-LTS-SP4</FullProductName>
			<FullProductName ProductID="openEuler-22.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">openEuler-22.03-LTS-SP4</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">openEuler-24.03-LTS</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS-SP1" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">openEuler-24.03-LTS-SP1</FullProductName>
			<FullProductName ProductID="openEuler-24.03-LTS-SP2" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">openEuler-24.03-LTS-SP2</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="src">
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-3.7.1-10.oe2403sp3.src.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-3.4.3-13.oe2003sp4.src.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-3.5.2-12.oe2203sp4.src.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-3.7.1-10.oe2403.src.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-3.7.1-10.oe2403sp1.src.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-3.7.1-10.oe2403sp2.src.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="noarch">
			<FullProductName ProductID="libarchive-help-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-help-3.7.1-10.oe2403sp3.noarch.rpm</FullProductName>
			<FullProductName ProductID="libarchive-help-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-help-3.4.3-13.oe2003sp4.noarch.rpm</FullProductName>
			<FullProductName ProductID="libarchive-help-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-help-3.5.2-12.oe2203sp4.noarch.rpm</FullProductName>
			<FullProductName ProductID="libarchive-help-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-help-3.7.1-10.oe2403.noarch.rpm</FullProductName>
			<FullProductName ProductID="libarchive-help-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-help-3.7.1-10.oe2403sp1.noarch.rpm</FullProductName>
			<FullProductName ProductID="libarchive-help-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-help-3.7.1-10.oe2403sp2.noarch.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="aarch64">
			<FullProductName ProductID="bsdcat-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">bsdcat-3.7.1-10.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">bsdcpio-3.7.1-10.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">bsdtar-3.7.1-10.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdunzip-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">bsdunzip-3.7.1-10.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-3.7.1-10.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-debuginfo-3.7.1-10.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-debugsource-3.7.1-10.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-devel-3.7.1-10.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-3.4.3-13.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-debuginfo-3.4.3-13.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-debugsource-3.4.3-13.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-devel-3.4.3-13.oe2003sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdcat-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">bsdcat-3.5.2-12.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">bsdcpio-3.5.2-12.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">bsdtar-3.5.2-12.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-3.5.2-12.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-debuginfo-3.5.2-12.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-debugsource-3.5.2-12.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-devel-3.5.2-12.oe2203sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdcat-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">bsdcat-3.7.1-10.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">bsdcpio-3.7.1-10.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">bsdtar-3.7.1-10.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdunzip-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">bsdunzip-3.7.1-10.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-3.7.1-10.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-debuginfo-3.7.1-10.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-debugsource-3.7.1-10.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-devel-3.7.1-10.oe2403.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdcat-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">bsdcat-3.7.1-10.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">bsdcpio-3.7.1-10.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">bsdtar-3.7.1-10.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdunzip-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">bsdunzip-3.7.1-10.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-3.7.1-10.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-debuginfo-3.7.1-10.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-debugsource-3.7.1-10.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-devel-3.7.1-10.oe2403sp1.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdcat-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">bsdcat-3.7.1-10.oe2403sp2.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">bsdcpio-3.7.1-10.oe2403sp2.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">bsdtar-3.7.1-10.oe2403sp2.aarch64.rpm</FullProductName>
			<FullProductName ProductID="bsdunzip-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">bsdunzip-3.7.1-10.oe2403sp2.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-3.7.1-10.oe2403sp2.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-debuginfo-3.7.1-10.oe2403sp2.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-debugsource-3.7.1-10.oe2403sp2.aarch64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-devel-3.7.1-10.oe2403sp2.aarch64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="x86_64">
			<FullProductName ProductID="bsdcat-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">bsdcat-3.7.1-10.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">bsdcpio-3.7.1-10.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">bsdtar-3.7.1-10.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdunzip-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">bsdunzip-3.7.1-10.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-3.7.1-10.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-debuginfo-3.7.1-10.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-debugsource-3.7.1-10.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">libarchive-devel-3.7.1-10.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-3.4.3-13.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-debuginfo-3.4.3-13.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-debugsource-3.4.3-13.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.4.3-13" CPE="cpe:/a:openEuler:openEuler:20.03-LTS-SP4">libarchive-devel-3.4.3-13.oe2003sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdcat-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">bsdcat-3.5.2-12.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">bsdcpio-3.5.2-12.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">bsdtar-3.5.2-12.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-3.5.2-12.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-debuginfo-3.5.2-12.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-debugsource-3.5.2-12.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.5.2-12" CPE="cpe:/a:openEuler:openEuler:22.03-LTS-SP4">libarchive-devel-3.5.2-12.oe2203sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdcat-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">bsdcat-3.7.1-10.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">bsdcpio-3.7.1-10.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">bsdtar-3.7.1-10.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdunzip-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">bsdunzip-3.7.1-10.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-3.7.1-10.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-debuginfo-3.7.1-10.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-debugsource-3.7.1-10.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS">libarchive-devel-3.7.1-10.oe2403.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdcat-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">bsdcat-3.7.1-10.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">bsdcpio-3.7.1-10.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">bsdtar-3.7.1-10.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdunzip-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">bsdunzip-3.7.1-10.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-3.7.1-10.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-debuginfo-3.7.1-10.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-debugsource-3.7.1-10.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP1">libarchive-devel-3.7.1-10.oe2403sp1.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdcat-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">bsdcat-3.7.1-10.oe2403sp2.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdcpio-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">bsdcpio-3.7.1-10.oe2403sp2.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdtar-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">bsdtar-3.7.1-10.oe2403sp2.x86_64.rpm</FullProductName>
			<FullProductName ProductID="bsdunzip-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">bsdunzip-3.7.1-10.oe2403sp2.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-3.7.1-10.oe2403sp2.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debuginfo-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-debuginfo-3.7.1-10.oe2403sp2.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-debugsource-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-debugsource-3.7.1-10.oe2403sp2.x86_64.rpm</FullProductName>
			<FullProductName ProductID="libarchive-devel-3.7.1-10" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP2">libarchive-devel-3.7.1-10.oe2403sp2.x86_64.rpm</FullProductName>
		</Branch>
	</ProductTree>
	<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.</Note>
		</Notes>
		<ReleaseDate>2026-03-20</ReleaseDate>
		<CVE>CVE-2026-4111</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP3</ProductID>
				<ProductID>openEuler-20.03-LTS-SP4</ProductID>
				<ProductID>openEuler-22.03-LTS-SP4</ProductID>
				<ProductID>openEuler-24.03-LTS</ProductID>
				<ProductID>openEuler-24.03-LTS-SP1</ProductID>
				<ProductID>openEuler-24.03-LTS-SP2</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>7.5</BaseScore>
				<Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>libarchive security update</Description>
				<DATE>2026-03-20</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1641</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
</cvrfdoc>