CVE-2026-101283: Buffer Overflow
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decryptrsamessage(): a 256-byte RSA buffer is BIOread with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
esnet/iperfto a version that resolves this vulnerability.Fixed in 3.22
Event History
Frequently Asked Questions
Which deployments are exposed to remote attack?
iperf3 versions 3.20 through 3.21 are affected when they accept client connections using the authentication-token path. An unauthenticated remote client can trigger the overflow by supplying an oversized authtoken ciphertext.
What is the recommended remediation?
Upgrade iperf3 to version 3.22, which fixes the issue.
What can be done if upgrading is not immediately possible?
Limit network access to affected iperf3 servers so untrusted clients cannot connect, especially where authentication-token handling is enabled. The vulnerable input is processed before authentication, so requiring clients to authenticate does not prevent exploitation.