Buffer Overflow Vulnerability in Iperf by ESnet
CVE-2025-54351

10CRITICAL

Key Information:

Vendor

Es

Status
Vendor
CVE Published:
3 August 2025

What is CVE-2025-54351?

A buffer overflow vulnerability exists in Iperf versions prior to 3.19.1. This vulnerability occurs when the '--skip-rx-copy' option is used in conjunction with MSG_TRUNC in the recv function, potentially allowing an attacker to exploit the overflow. Users of these affected versions are advised to update their software promptly to the latest version to mitigate the risks associated with this issue.

Affected Version(s)

iperf3 0 < 3.19.1

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.
CVE-2025-54351 : Buffer Overflow Vulnerability in Iperf by ESnet