iperf3-3.9-17.el9_8.1

エラータID: AXSA:2026-1734:06

Release date: 
Wednesday, September 2, 2026 - 16:48
Subject: 
iperf3-3.9-17.el9_8.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.

Security Fix(es):

* iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion (CVE-2026-71217)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-71217
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. iperf3-3.9-17.el9_8.1.src.rpm
    MD5: 596009d05175829089ee09c964611fcb
    SHA-256: 1484b8e8269aa2247cee251b221336ad4815ae4e5622d9a11c5549e450b307e4
    Size: 636.29 kB

Asianux Server 9 for x86_64
  1. iperf3-3.9-17.el9_8.1.i686.rpm
    MD5: a0adbcbcc27ffc2595aef2bc8139a132
    SHA-256: 84566bbfc793dc1929e41113f372082f091e5ffad1b015fe2dd2ea82b1d113ec
    Size: 115.81 kB
  2. iperf3-3.9-17.el9_8.1.x86_64.rpm
    MD5: 2795c1016907e57869e0d5592d6da0b1
    SHA-256: aec63673b31fb0da807e1f8da60ba204f2d191a21f5dd256099adbc60d44d550
    Size: 107.16 kB