Iperf3 · Iperf3 · CVE-2026-101276
**Name of the Vulnerable Software and Affected Versions**
iperf3 version 3.21
**Description**
A remote, unauthenticated heap use-after-free exists in the server. The per-test watchdog function `server timer proc()` frees streams without cancelling or joining their worker threads, which can lead to a blocked worker dereferencing a freed `iperf stream`. A heap use-after-free occurs when a program continues to use a pointer after the memory it points to has been freed.
**Recommendations**
Update iperf3 to version 3.22.