Search CVE reports


Toggle filters

1 – 10 of 12 results


CVE-2026-71218

Medium priority
Needs evaluation

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the...

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-71217

Medium priority
Needs evaluation

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server....

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-67216

Medium priority
Needs evaluation

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the...

4 affected packages

cjson, iperf3, mapcache, sail-ocaml

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cjson Needs evaluation Needs evaluation Needs evaluation Needs evaluation
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
mapcache Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
sail-ocaml Needs evaluation Not in release Not in release
Show less packages

CVE-2025-54351

Medium priority
Needs evaluation

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-54350

Medium priority

Some fixes available 4 of 5

In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Fixed Fixed Fixed Not affected
Show less packages

CVE-2025-54349

Medium priority

Some fixes available 4 of 5

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-53580

Medium priority

Some fixes available 3 of 15

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

2 affected packages

iperf, iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
iperf3 Not affected Fixed Fixed Fixed Ignored
Show less packages

CVE-2024-26306

Medium priority

Some fixes available 3 of 8

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential...

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Fixed Fixed Fixed Ignored
Show less packages

CVE-2023-26306

Medium priority

Some fixes available 3 of 8

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential...

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Fixed Fixed Fixed Ignored
Show less packages

CVE-2023-7250

Medium priority

Some fixes available 4 of 5

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to...

1 affected package

iperf3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Fixed Fixed Fixed
Show less packages