CVE-2026-101276: Use After Free
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog servertimerproc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperfstream; fixed in 3.22.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
esnet/iperfto a version that resolves this vulnerability.Fixed in 3.22
Event History
Frequently Asked Questions
Which deployments are exposed?
iperf3 version 3.21 servers are affected. The issue is remotely reachable and requires no authentication or user interaction, so any reachable iperf3 server running that version is exposed.
What does an attacker need to do to exploit this?
An attacker needs network access to the iperf3 server and must trigger a test condition in which a worker thread remains blocked while the server watchdog frees its associated stream. No credentials are required.
What is the remediation?
Upgrade iperf3 from 3.21 to version 3.22, which fixes the issue.