rpm package
almalinux/iperf3
pkg:rpm/almalinux/iperf3
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-54349 | — | < 3.5-12.el8_10 | 3.5-12.el8_10 | Aug 3, 2025 | In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow. | ||
| CVE-2024-53580 | — | < 3.9-13.el9_5.1 | 3.9-13.el9_5.1 | Dec 18, 2024 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. | ||
| CVE-2024-26306 | — | < 3.5-10.el8_10 | 3.5-10.el8_10 | May 13, 2024 | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large | ||
| CVE-2023-7250 | — | < 3.5-10.el8_10 | 3.5-10.el8_10 | Mar 18, 2024 | A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or unt | ||
| CVE-2023-38403 | — | < 3.5-7.el8_8.alma | 3.5-7.el8_8.alma | Jul 17, 2023 | iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. |
- CVE-2025-54349Aug 3, 2025affected < 3.5-12.el8_10fixed 3.5-12.el8_10
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
- CVE-2024-53580Dec 18, 2024affected < 3.9-13.el9_5.1fixed 3.9-13.el9_5.1
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
- CVE-2024-26306May 13, 2024affected < 3.5-10.el8_10fixed 3.5-10.el8_10
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large
- CVE-2023-7250Mar 18, 2024affected < 3.5-10.el8_10fixed 3.5-10.el8_10
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or unt
- CVE-2023-38403Jul 17, 2023affected < 3.5-7.el8_8.almafixed 3.5-7.el8_8.alma
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.