Heap Buffer Overflow in iperf3 Affects esnet
CVE-2026-101283

9.2CRITICAL

Key Information:

Vendor

Esnet

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-101283?

The iperf3 application, particularly versions 3.20 to 3.21, contains a heap buffer overflow vulnerability in the decrypt_rsa_message function. This flaw arises from the handling of an attacker-controlled ciphertext length during a pre-auth stage, allowing an unauthenticated client to exploit the application. By sending an oversized authtoken, an attacker can manipulate the heap memory, potentially leading to arbitrary code execution. The vulnerability has been addressed in version 3.22, which includes necessary fixes.

Affected Version(s)

iperf3 3.20

iperf3 3.21

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anthropic
Ada Logics
.