A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade iperf3 | Jul 4, 2024 | Mar 18, 2024 |
| Amazon Linux Ami 2 | — | Upgrade iperf3Upgrade iperf3-debuginfoUpgrade iperf3-devel | Jun 26, 2024 | Mar 18, 2024 |
| Debian | — | Upgrade iperf3 | Jan 30, 2025 | Mar 18, 2024 |
| Oracle_linux | — | Upgrade iperf3 | Jul 3, 2024 | Oct 16, 2023 |
| Redhat_linux | — | Upgrade iperf3No solution existsUpgrade iperf3-debugsourceUpgrade iperf3-debuginfo | Jul 3, 2024 | Mar 18, 2024 |
| Rocky_linux | — | Upgrade iperf3-debugsourceUpgrade iperf3Upgrade iperf3-debuginfo | Mar 18, 2025 | Mar 18, 2024 |
| Ubuntu | — | Upgrade iperf3 (Ubuntu Pro)Upgrade libiperf0 (Ubuntu Pro)Upgrade libiperf0Upgrade iperf3 | Jan 22, 2026 | Jan 21, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 18, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub