Denial of Service Vulnerability in iperf3 by Red Hat
CVE-2026-71217
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 11 August 2026
Badges
What is CVE-2026-71217?
A vulnerability exists in iperf3 that allows remote attackers to exploit flawed input validation of control-channel JSON data. By submitting oversized numeric parameters such as 'parallel' and 'len', an attacker can provoke the server into creating excessive streams and threads, leading to large buffer allocations. This condition can deplete system resources, which ultimately may render the iperf3 server inoperable, resulting in a Denial of Service.
Affected Version(s)
Red Hat Enterprise Linux 10 0:3.17.1-6.el10_2.1
Red Hat Enterprise Linux 8 0:3.5-12.el8_10.1
Red Hat Enterprise Linux 9 0:3.9-17.el9_8.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved