CVE-2026-101283
Received Received - Intake

Heap Buffer Overflow in iperf3

Vulnerability report for CVE-2026-101283, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: 98a01053-8a31-4f6d-9aa9-252be161adc6

Description

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
esnet iperf3 to 3.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

iperf3 versions 3.20 to 3.21 contain a pre-authentication heap buffer overflow in the decrypt_rsa_message() function. An unauthenticated attacker can send a maliciously crafted authtoken that exceeds the 256-byte RSA buffer size, leading to heap memory corruption.

Detection Guidance

This vulnerability can be detected by checking the version of iperf3 installed on your system. Run 'iperf3 --version' to see if it falls within the vulnerable range of 3.20 to 3.21. Additionally, monitor network traffic for unusual patterns or crashes in iperf3 processes.

Impact Analysis

This vulnerability allows remote attackers to execute arbitrary code or cause denial-of-service conditions on systems running vulnerable iperf3 versions. It does not require authentication, making it particularly dangerous for exposed services.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a technical flaw in iperf3's RSA decryption process. However, if exploited, it could lead to unauthorized access or data breaches, which may indirectly impact compliance by violating data protection requirements.

Mitigation Strategies

Immediately upgrade iperf3 to version 3.22 or later. If upgrading is not possible, consider disabling the service or restricting network access to it until the update is applied. Monitor for any signs of exploitation or unusual activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101283. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart