Heap Use-After-Free Vulnerability in Iperf3 by ESnet
CVE-2026-101276
9.2CRITICAL
What is CVE-2026-101276?
Iperf3 version 3.21 contains a vulnerability that allows remote, unauthenticated attackers to exploit a heap use-after-free condition. Specifically, the watchdog server_timer_proc() does not properly manage the freeing of streams, which can lead to a situation where a blocked worker thread accesses a freed iperf_stream. This flaw can be exploited to cause undefined behavior or system crashes, affecting server stability. The issue has been addressed in the subsequent release 3.22.
Affected Version(s)
iperf3 3.21
