PT-2026-103607 · Iperf3 · Iperf3

·

CVE-2026-101276

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions iperf3 version 3.21
Description A remote, unauthenticated heap use-after-free exists in the server. The per-test watchdog function server timer proc() frees streams without cancelling or joining their worker threads, which can lead to a blocked worker dereferencing a freed iperf stream. A heap use-after-free occurs when a program continues to use a pointer after the memory it points to has been freed.
Recommendations Update iperf3 to version 3.22.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101276

Affected Products

Iperf3