We believe that the bug you reported is fixed in the latest version of
iperf3, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1149699@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Daniel Baumann <daniel@debian.org> (supplier of updated iperf3 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 02 Oct 2026 14:52:21 +0200
Source: iperf3
Architecture: source
Version: 3.22-0.1
Distribution: sid
Urgency: high
Maintainer: Roberto Lumbreras <rover@debian.org>
Changed-By: Daniel Baumann <daniel@debian.org>
Closes: 1144390 1149699
Changes:
iperf3 (3.22-0.1) sid; urgency=high
.
* Non-maintainer upload.
* New upstream release (Closes: #1144390, #1149699), any operators of public
iperf3 servers are strongly recommended to upgrade:
- iperf3 server accepts unbounded peer-controlled json parameters enabling
remote denial of service via resource exhaustion [CVE-2026-71217].
- iperf3 contains a remote, unauthenticated heap use-after-free: the
server's per-test watchdog server_timer_proc() frees streams without
cancelling/joining their worker threads, so a blocked worker
dereferences a freed iperf_stream [CVE-2026-101276].
- iperf3 has a pre-auth heap buffer overflow in decrypt_rsa_message(): a
256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext
length (guard warns only), so an unauthenticated client overflows the
heap via an oversized authtoken [CVE-2026-101283].
- iperf3 contains a denial of service ulnerability that allows
unauthenticated remote attackers to crash-loop the server's UDP receive
worker into an unrecoverable infinite loop by sending a single crafted
control-channel parameter message followed by one 16-byte UDP datagram.
Attackers can permanently pin the affected per-stream receive thread at
approximately 100% CPU usage, rendering the server unusable until
forcibly killed with SIGKILL, as the process does not respond to normal
control-channel closure [CVE-2026-102253].
* Updating libiperf0 symbols for new upstream release.
Checksums-Sha1:
9c6a812984b14d6d3274da09c3b18e35e6a1dad5 1353 iperf3_3.22-0.1.dsc
e73f18745e00b863d6d77be75bfbfc90b7521281 638780 iperf3_3.22.orig.tar.xz
09d021ada2b60b9e0d2abb976f82fbaade4f852e 17108 iperf3_3.22-0.1.debian.tar.xz
8311b947ea3893b533348559f88735e5c752b3cd 6171 iperf3_3.22-0.1_amd64.buildinfo
Checksums-Sha256:
3ec85260cae75426c0a72e93fd2d24c7351bdea5120f86815ab63f15a9bec207 1353 iperf3_3.22-0.1.dsc
88ece405c56e70d1504e220b5ae3805bd1aaed40efd160e83a49a9aa0d734c45 638780 iperf3_3.22.orig.tar.xz
4501e4c42e93f8811e5ba6594ad82318e2fccb240ac0bd1ed9987fb653bb77d2 17108 iperf3_3.22-0.1.debian.tar.xz
069aa296167ccd4c2b2553a8710c6135769d74c6c986d6831b1c861644cbfaa2 6171 iperf3_3.22-0.1_amd64.buildinfo
Files:
cc4a657b03c6f96c85aceb974781c54e 1353 net optional iperf3_3.22-0.1.dsc
f572295b83d81879416b7727b080c0ab 638780 net optional iperf3_3.22.orig.tar.xz
85159810f3593973fde1afefef39a894 17108 net optional iperf3_3.22-0.1.debian.tar.xz
b2e2f8d63d847e88d117ff6f46158ceb 6171 net optional iperf3_3.22-0.1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQQmmGg4gLaoSj0ERgL7tPDoCoAiLwUCar+rfAAKCRD7tPDoCoAi
L5VUAP9HQVwEYGgsz2Pqsko2N706AFK1hm+8tkatxnZFqLrm+AEA9rxiPTFcS0ce
D+4e4a8sIw31P27ShGnYc1wRqCrSIgQ=
=8fji
-----END PGP SIGNATURE-----