<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:37:39 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:4241 — Moderate: iperf3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4241</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* iperf3: possible denial of service (CVE-2023-7250)
* iperf3: vulnerable to marvin attack if the authentication option is used (CVE-2024-26306)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* iperf3: possible denial of service (CVE-2023-7250)
* iperf3: vulnerable to marvin attack if the authentication option is used (CVE-2024-26306)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4241</guid>
    </item>
    <item>
      <title>bdu:2024-03238</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-03238</link>
      <description>bdu:2024-03238</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-03238</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0113 — De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0113</link>
      <description>certfr-2025-avi-0113</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0113</guid>
    </item>
    <item>
      <title>EUVD-2026-260283</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260283</link>
      <description>EUVD-2026-260283</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260283</guid>
    </item>
    <item>
      <title>fkie_cve-2023-7250</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-7250</link>
      <description>&lt;p&gt;A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-7250</guid>
    </item>
    <item>
      <title>GHSA-g636-8hgg-7gx9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g636-8hgg-7gx9</link>
      <description>&lt;p&gt;A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g636-8hgg-7gx9</guid>
    </item>
    <item>
      <title>gsd-2023-7250</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-7250</link>
      <description>gsd-2023-7250</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-7250</guid>
    </item>
    <item>
      <title>ICSA-25-044-09 — Siemens SCALANCE W700 IEEE 802.11ax</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-044-09</link>
      <description>&lt;p&gt;Zhenpeng Lin discovered that the network packet scheduler implementation in the Linux kernel did not properly remove all references to a route filter before freeing it in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured. A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211021 was assigned to this vulnerability. A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Zhenpeng Lin discovered that the network packet scheduler implementation in the Linux kernel did not properly remove all references to a route filter before freeing it in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured. A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function ipv6_renew_options of the component IPv6 Handler. The manipulation leads to memory leak. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211021 was assigned to this vulnerability. A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-044-09</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-7250 — Iperf3: possible denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-7250</link>
      <description>msrc_CVE-2023-7250</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-7250</guid>
    </item>
    <item>
      <title>OESA-2024-1418 — iperf3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1418</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: iperf3, openEuler:20.03-LTS-SP4: iperf3, openEuler:22.03-LTS: iperf3, openEuler:22.03-LTS-SP1: iperf3, openEuler:22.03-LTS-SP2: iperf3, openEuler:22.03-LTS-SP3: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool for active measurements of the maximum achievable bandwidth on IP networks. It supports tuning of various parameters related to timing, protocols, and buffers.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.(CVE-2023-7250)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: iperf3, openEuler:20.03-LTS-SP4: iperf3, openEuler:22.03-LTS: iperf3, openEuler:22.03-LTS-SP1: iperf3, openEuler:22.03-LTS-SP2: iperf3, openEuler:22.03-LTS-SP3: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool for active measurements of the maximum achievable bandwidth on IP networks. It supports tuning of various parameters related to timing, protocols, and buffers.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.(CVE-2023-7250)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1418</guid>
    </item>
    <item>
      <title>RHSA-2024:4241 — Red Hat Security Advisory: iperf3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:4241</link>
      <description>&lt;p&gt;iperf3: possible denial of service iperf3: vulnerable to marvin attack if the authentication option is used&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;iperf3: possible denial of service iperf3: vulnerable to marvin attack if the authentication option is used&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:4241</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-7250</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-7250</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: iperf3, Ubuntu:Pro:18.04:LTS: iperf3, Ubuntu:Pro:20.04:LTS: iperf3, Ubuntu:22.04:LTS: iperf3&lt;/p&gt;
&lt;p&gt;A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: iperf3, Ubuntu:Pro:18.04:LTS: iperf3, Ubuntu:Pro:20.04:LTS: iperf3, Ubuntu:22.04:LTS: iperf3&lt;/p&gt;
&lt;p&gt;A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-7250</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1510 — Red Hat Enterprise Linux (iperf3): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1510</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Kpomponente iperf3 ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Kpomponente iperf3 ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1510</guid>
    </item>
  </channel>
</rss>
