Executive brief
iperf3 is a network performance measurement tool widely used to test bandwidth and network characteristics. A flaw in the server allows remote attackers to send specially crafted control-channel messages that cause excessive resource consumption, crashing the iperf3 server and disrupting network testing and monitoring operations.
Technical details
The vulnerability is an improper input validation flaw in iperf3's JSON control-channel parser. An unauthenticated remote attacker can send control messages with oversized numeric parameters (such as `parallel` and `len`) that are not properly validated. These parameters trigger unbounded stream and thread creation as well as large buffer allocations, exhausting server memory and CPU resources and causing a Denial of Service. The flaw affects the iperf3 server component and requires only network reachability; no authentication is needed. Patches are available in Red Hat Enterprise Linux 8 update RHSA-2026:61257.
Affected products
- iperf iperf3 3.5 and earlier
Timeline
- 2026-08-11: disclosed
- 2026-08-31: patched: Red Hat Enterprise Linux 8 patch released as RHSA-2026:61257