<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 22:42:33 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:61257 — Important: iperf3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:61257</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion (CVE-2026-71217)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion (CVE-2026-71217)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:61257</guid>
    </item>
    <item>
      <title>EUVD-2026-361895</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361895</link>
      <description>EUVD-2026-361895</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361895</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71217</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71217</link>
      <description>&lt;p&gt;A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71217</guid>
    </item>
    <item>
      <title>GHSA-4jvc-h3x3-w6qj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4jvc-h3x3-w6qj</link>
      <description>&lt;p&gt;A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4jvc-h3x3-w6qj</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-71217 — Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabling remote denial of service via resource…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-71217</link>
      <description>msrc_CVE-2026-71217</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-71217</guid>
    </item>
    <item>
      <title>OESA-2026-3527 — iperf3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3527</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: iperf3, openEuler:24.03-LTS-SP4: iperf3, openEuler:20.03-LTS-SP4: iperf3, openEuler:22.03-LTS-SP4: iperf3, openEuler:24.03-LTS-SP1: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool for active measurements of the maximum achievable bandwidth on IP networks. It supports tuning of various parameters related to timing, protocols, and buffers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.(CVE-2026-71217)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: iperf3, openEuler:24.03-LTS-SP4: iperf3, openEuler:20.03-LTS-SP4: iperf3, openEuler:22.03-LTS-SP4: iperf3, openEuler:24.03-LTS-SP1: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool for active measurements of the maximum achievable bandwidth on IP networks. It supports tuning of various parameters related to timing, protocols, and buffers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.(CVE-2026-71217)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3527</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:12060-1 — iperf-3.22-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:12060-1</link>
      <description>&lt;p&gt;iperf-3.22-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;iperf-3.22-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:12060-1</guid>
    </item>
    <item>
      <title>RLSA-2026:61257 — Important: iperf3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:61257</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion (CVE-2026-71217)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: iperf3&lt;/p&gt;
&lt;p&gt;Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion (CVE-2026-71217)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:61257</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-71217</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71217</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: iperf3, Ubuntu:Pro:18.04:LTS: iperf3, Ubuntu:Pro:20.04:LTS: iperf3, Ubuntu:Pro:22.04:LTS: iperf3, Ubuntu:Pro:24.04:LTS: iperf3, Ubuntu:26.04:LTS: iperf3&lt;/p&gt;
&lt;p&gt;A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: iperf3, Ubuntu:Pro:18.04:LTS: iperf3, Ubuntu:Pro:20.04:LTS: iperf3, Ubuntu:Pro:22.04:LTS: iperf3, Ubuntu:Pro:24.04:LTS: iperf3, Ubuntu:26.04:LTS: iperf3&lt;/p&gt;
&lt;p&gt;A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71217</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3080 — Red Hat Enterprise Linux (iperf3): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3080</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3080</guid>
    </item>
  </channel>
</rss>
