CVE-2026-101283
Published: October 5, 2026Last modified: October 7, 2026
Description
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | iperf3 | Not affected (3.12-r0) |
| 25 LTS | iperf3 | Not affected (3.19-r0) | |
| Stream | iperf3 | Vulnerable (3.12-r0) |