Upstream information

CVE-2026-71217 at MITRE

Description

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v3 Scores
CVSS detail CNA (Red Hat)
Base Score 7.5
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
CVSSv3 Version 3.1
No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 10
  • iperf3 >= 3.17.1-6.el10_2.1
Patchnames:
RHSA-2026:61680 (x86_64)
SUSE Liberty Linux 8
  • iperf3 >= 3.5-12.el8_10.1
Patchnames:
RHSA-2026:61257 (i686,x86_64)
SUSE Liberty Linux 9
  • iperf3 >= 3.9-17.el9_8.1
Patchnames:
RHSA-2026:61389 (i686,x86_64)


SUSE Timeline for this CVE

CVE page created: Mon Aug 31 16:49:59 2026
CVE page last modified: Tue Sep 1 15:08:18 2026