#1144390 iperf3: CVE-2026-71217

Package:
src:iperf3
Source:
src:iperf3
Submitter:
Salvatore Bonaccorso
Date:
2026-10-02 13:23:03 UTC
Severity:
normal
Tags:
#1144390#5
Date:
2026-08-14 14:49:38 UTC
From:
To:
Hi,

The following vulnerability was published for iperf3.

CVE-2026-71217[0]:
| A flaw was found in iperf3. A remote attacker can exploit this
| vulnerability by sending crafted control-channel JSON with oversized
| numeric parameters, such as `parallel` and `len`, which are not
| properly validated by the server. This improper input validation can
| lead to excessive stream and thread creation, as well as large
| buffer allocations, causing resource exhaustion. Consequently, this
| can result in a Denial of Service (DoS) on the affected iperf3
| server.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-71217
https://www.cve.org/CVERecord?id=CVE-2026-71217
[1] https://github.com/esnet/iperf/commit/494dd377eca4689672becdf06a85158557db1586

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144390#10
Date:
2026-10-02 13:21:05 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
iperf3, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144390@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Daniel Baumann <daniel@debian.org> (supplier of updated iperf3 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 02 Oct 2026 14:52:21 +0200
Source: iperf3
Architecture: source
Version: 3.22-0.1
Distribution: sid
Urgency: high
Maintainer: Roberto Lumbreras <rover@debian.org>
Changed-By: Daniel Baumann <daniel@debian.org>
Closes: 1144390 1149699
Changes:
 iperf3 (3.22-0.1) sid; urgency=high
 .
   * Non-maintainer upload.
   * New upstream release (Closes: #1144390, #1149699), any operators of public
     iperf3 servers are strongly recommended to upgrade:
     - iperf3 server accepts unbounded peer-controlled json parameters enabling
       remote denial of service via resource exhaustion [CVE-2026-71217].
     - iperf3 contains a remote, unauthenticated heap use-after-free: the
       server's per-test watchdog server_timer_proc() frees streams without
       cancelling/joining their worker threads, so a blocked worker
       dereferences a freed iperf_stream [CVE-2026-101276].
     - iperf3 has a pre-auth heap buffer overflow in decrypt_rsa_message(): a
       256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext
       length (guard warns only), so an unauthenticated client overflows the
       heap via an oversized authtoken [CVE-2026-101283].
     - iperf3 contains a denial of service  ulnerability that allows
       unauthenticated remote attackers to crash-loop the server's UDP receive
       worker into an unrecoverable infinite loop by sending a single crafted
       control-channel parameter message followed by one 16-byte UDP datagram.
       Attackers can permanently pin the affected per-stream receive thread at
       approximately 100% CPU usage, rendering the server unusable until
       forcibly killed with SIGKILL, as the process does not respond to normal
       control-channel closure [CVE-2026-102253].
   * Updating libiperf0 symbols for new upstream release.
Checksums-Sha1:
 9c6a812984b14d6d3274da09c3b18e35e6a1dad5 1353 iperf3_3.22-0.1.dsc
 e73f18745e00b863d6d77be75bfbfc90b7521281 638780 iperf3_3.22.orig.tar.xz
 09d021ada2b60b9e0d2abb976f82fbaade4f852e 17108 iperf3_3.22-0.1.debian.tar.xz
 8311b947ea3893b533348559f88735e5c752b3cd 6171 iperf3_3.22-0.1_amd64.buildinfo
Checksums-Sha256:
 3ec85260cae75426c0a72e93fd2d24c7351bdea5120f86815ab63f15a9bec207 1353 iperf3_3.22-0.1.dsc
 88ece405c56e70d1504e220b5ae3805bd1aaed40efd160e83a49a9aa0d734c45 638780 iperf3_3.22.orig.tar.xz
 4501e4c42e93f8811e5ba6594ad82318e2fccb240ac0bd1ed9987fb653bb77d2 17108 iperf3_3.22-0.1.debian.tar.xz
 069aa296167ccd4c2b2553a8710c6135769d74c6c986d6831b1c861644cbfaa2 6171 iperf3_3.22-0.1_amd64.buildinfo
Files:
 cc4a657b03c6f96c85aceb974781c54e 1353 net optional iperf3_3.22-0.1.dsc
 f572295b83d81879416b7727b080c0ab 638780 net optional iperf3_3.22.orig.tar.xz
 85159810f3593973fde1afefef39a894 17108 net optional iperf3_3.22-0.1.debian.tar.xz
 b2e2f8d63d847e88d117ff6f46158ceb 6171 net optional iperf3_3.22-0.1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQmmGg4gLaoSj0ERgL7tPDoCoAiLwUCar+rfAAKCRD7tPDoCoAi
L5VUAP9HQVwEYGgsz2Pqsko2N706AFK1hm+8tkatxnZFqLrm+AEA9rxiPTFcS0ce
D+4e4a8sIw31P27ShGnYc1wRqCrSIgQ=
=8fji
-----END PGP SIGNATURE-----