Search CVE reports


Toggle filters

1 – 10 of 15 results


CVE-2026-101283

Medium priority
Needs evaluation

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client...

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-101276

Medium priority
Needs evaluation

iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a...

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-102253

Medium priority
Needs evaluation

iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted...

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71218

Medium priority
Needs evaluation

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the...

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71217

Medium priority
Needs evaluation

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server....

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-67216

Medium priority
Vulnerable

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the...

4 affected packages

cjson, iperf3, mapcache, sail-ocaml

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Vulnerable Vulnerable Vulnerable Vulnerable —
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mapcache Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
sail-ocaml Needs evaluation Not in release Not in release — —
Show less packages

CVE-2025-54351

Medium priority
Needs evaluation

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not affected
Show less packages

CVE-2025-54350

Medium priority

Some fixes available 4 of 5

In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Fixed Fixed Fixed Not affected
Show less packages

CVE-2025-54349

Medium priority

Some fixes available 4 of 5

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-53580

Medium priority

Some fixes available 3 of 15

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

2 affected packages

iperf, iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
iperf3 Not affected Fixed Fixed Fixed Ignored
Show less packages