CVE-2026-101283
9.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| esnet | iperf3 | 3.20 | affected |
| esnet | iperf3 | 3.21 | affected |
Weaknesses
- CWE-122: CWE-122 Heap-based buffer overflow
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.