Heap Use-After-Free Vulnerability in Iperf3 by ESnet
CVE-2026-101276

9.2CRITICAL

Key Information:

Vendor

Esnet

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-101276?

Iperf3 version 3.21 contains a vulnerability that allows remote, unauthenticated attackers to exploit a heap use-after-free condition. Specifically, the watchdog server_timer_proc() does not properly manage the freeing of streams, which can lead to a situation where a blocked worker thread accesses a freed iperf_stream. This flaw can be exploited to cause undefined behavior or system crashes, affecting server stability. The issue has been addressed in the subsequent release 3.22.

Affected Version(s)

iperf3 3.21

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anthropic
Ada Logics
.