PT-2026-103621 · Iperf3 · Iperf3

·

CVE-2026-101283

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions iperf3 versions 3.20 through 3.21
Description A pre-authentication heap buffer overflow exists in the decrypt rsa message() function. This occurs because a 256-byte RSA buffer is read using a ciphertext length controlled by the attacker, allowing an unauthenticated client to overflow the heap by providing an oversized authtoken.
Recommendations Update iperf3 to version 3.22.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101283

Affected Products

Iperf3