<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:49:27 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:4241 — Moderate: iperf3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4241</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* iperf3: possible denial of service (CVE-2023-7250)
* iperf3: vulnerable to marvin attack if the authentication option is used (CVE-2024-26306)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* iperf3: possible denial of service (CVE-2023-7250)
* iperf3: vulnerable to marvin attack if the authentication option is used (CVE-2024-26306)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4241</guid>
    </item>
    <item>
      <title>bdu:2024-04484</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04484</link>
      <description>bdu:2024-04484</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04484</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-26306</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-26306</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: iperf3, Alpaquita:stream: iperf3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: iperf3, Alpaquita:stream: iperf3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-26306</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0968 — De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un atta…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0968</link>
      <description>certfr-2024-avi-0968</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0968</guid>
    </item>
    <item>
      <title>EUVD-2026-258108</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258108</link>
      <description>EUVD-2026-258108</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258108</guid>
    </item>
    <item>
      <title>fkie_cve-2024-26306</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26306</link>
      <description>&lt;p&gt;iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in &amp;#34;Everlasting ROBOT: the Marvin Attack&amp;#34; by Hubert Kario.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in &amp;#34;Everlasting ROBOT: the Marvin Attack&amp;#34; by Hubert Kario.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-26306</guid>
    </item>
    <item>
      <title>GHSA-x8qh-8j65-v4j9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x8qh-8j65-v4j9</link>
      <description>&lt;p&gt;iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in &amp;#34;Everlasting ROBOT: the Marvin Attack&amp;#34; by Hubert Kario.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in &amp;#34;Everlasting ROBOT: the Marvin Attack&amp;#34; by Hubert Kario.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x8qh-8j65-v4j9</guid>
    </item>
    <item>
      <title>gsd-2024-26306</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-26306</link>
      <description>gsd-2024-26306</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-26306</guid>
    </item>
    <item>
      <title>ICSA-24-319-06 — Siemens SCALANCE M-800 Family</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-319-06</link>
      <description>&lt;p&gt;An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020. dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query. Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions&#13;
Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The F…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020. dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query. Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions&#13;
Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The F…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-319-06</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-26306 — iPerf3 before 3.17 when used with OpenSSL before 3.2.0 as a server with RSA authentication allows a timing side channel…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-26306</link>
      <description>msrc_CVE-2024-26306</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-26306</guid>
    </item>
    <item>
      <title>OESA-2024-1604 — iperf3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1604</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: iperf3, openEuler:22.03-LTS: iperf3, openEuler:22.03-LTS-SP1: iperf3, openEuler:22.03-LTS-SP3: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool for active measurements of the maximum achievable bandwidth on IP networks. It supports tuning of various parameters related to timing, protocols, and buffers.&#13;
&#13;
Security Fix(es):&#13;
&#13;
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in &amp;amp;quot;Everlasting ROBOT: the Marvin Attack&amp;amp;quot; by Hubert Kario.(CVE-2024-26306)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: iperf3, openEuler:22.03-LTS: iperf3, openEuler:22.03-LTS-SP1: iperf3, openEuler:22.03-LTS-SP3: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool for active measurements of the maximum achievable bandwidth on IP networks. It supports tuning of various parameters related to timing, protocols, and buffers.&#13;
&#13;
Security Fix(es):&#13;
&#13;
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in &amp;amp;quot;Everlasting ROBOT: the Marvin Attack&amp;amp;quot; by Hubert Kario.(CVE-2024-26306)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1604</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13964-1 — iperf-3.17.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13964-1</link>
      <description>&lt;p&gt;iperf-3.17.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;iperf-3.17.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13964-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1981-1 — Security update for iperf</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1981-1</link>
      <description>&lt;p&gt;Security update for iperf&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for iperf&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1981-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-26306</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26306</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: iperf3, Ubuntu:Pro:18.04:LTS: iperf3, Ubuntu:Pro:20.04:LTS: iperf3, Ubuntu:22.04:LTS: iperf3, Ubuntu:Pro:24.04:LTS: iperf3&lt;/p&gt;
&lt;p&gt;iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in &amp;#34;Everlasting ROBOT: the Marvin Attack&amp;#34; by Hubert Kario.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: iperf3, Ubuntu:Pro:18.04:LTS: iperf3, Ubuntu:Pro:20.04:LTS: iperf3, Ubuntu:22.04:LTS: iperf3, Ubuntu:Pro:24.04:LTS: iperf3&lt;/p&gt;
&lt;p&gt;iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in &amp;#34;Everlasting ROBOT: the Marvin Attack&amp;#34; by Hubert Kario.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26306</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1510 — Red Hat Enterprise Linux (iperf3): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1510</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Kpomponente iperf3 ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Kpomponente iperf3 ausnutzen, um einen Denial of Service Angriff durchzuführen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1510</guid>
    </item>
  </channel>
</rss>
