CVE-2026-102253

NameCVE-2026-102253
Descriptioniperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
iperf3 (PTS)bookworm3.12-1+deb12u2vulnerable
bookworm (security)3.12-1+deb12u1vulnerable
trixie3.18-2+deb13u2vulnerable
forky, sid3.20-2.1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iperf3source(unstable)(unfixed)

Notes

https://github.com/esnet/iperf/commit/a25378f8cbbaa7b3db5674ca3dcc19658ae65da3 (3.22)
https://github.com/esnet/iperf/releases/tag/3.22

Search for package or bug name: Reporting problems