CVE-2026-71217

NameCVE-2026-71217
DescriptionA flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
iperf3 (PTS)bullseye3.9-1+deb11u1vulnerable
bullseye (security)3.9-1+deb11u3vulnerable
bookworm3.12-1+deb12u2vulnerable
bookworm (security)3.12-1+deb12u1vulnerable
trixie3.18-2+deb13u2vulnerable
forky, sid3.20-2.1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
iperf3source(unstable)(unfixed)

Notes

[trixie] - iperf3 <no-dsa> (Minor issue)
[bookworm] - iperf3 <postponed> (Minor issue)
[bullseye] - iperf3 <postponed> (Minor issue)
https://bugzilla.redhat.com/show_bug.cgi?id=2460984
https://github.com/esnet/iperf/commit/494dd377eca4689672becdf06a85158557db1586

Search for package or bug name: Reporting problems