Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71218

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the JSON_read() function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the iperf3 control port, ensuring it is only reachable by trusted clients. This can be achieved by configuring firewall rules to limit inbound connections to the iperf3 service. Additionally, consider running the iperf3 service within environments that enforce process or container memory limits to further contain potential resource exhaustion. Note that authentication alone is insufficient as the memory allocation occurs before authentication checks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10iperf3Fix deferred
Red Hat Enterprise Linux 7iperf3Fix deferred
Red Hat Enterprise Linux 8iperf3Fix deferred
Red Hat Enterprise Linux 9iperf3Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-789
https://bugzilla.redhat.com/show_bug.cgi?id=2463003iperf3: Unbounded peer-controlled allocation in iperf3 JSON_read() allows unauthenticated remote memory exhaustion

EPSS

Процентиль: 31%
0.00383
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
20 дней назад

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.

CVSS3: 5.3
nvd
20 дней назад

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.

CVSS3: 5.3
msrc
17 дней назад

Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion

CVSS3: 5.3
debian
20 дней назад

A flaw was found in iperf3. A remote unauthenticated attacker can expl ...

CVSS3: 5.3
github
20 дней назад

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.

EPSS

Процентиль: 31%
0.00383
Низкий

5.3 Medium

CVSS3