{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/iperf3--3.22/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:esnet:iperf:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-102253"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=CC42D07B-7705-5A4E-84F6-87763B01ED80\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["iperf3 (\u003c 3.22)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","network-security","cve-2026-102253"],"_cs_type":"advisory","_cs_vendors":["ESnet"],"content_html":"\u003cp\u003eiperf3 versions prior to 3.22 contain a critical denial of service (DoS) vulnerability, tracked as CVE-2026-102253. The vulnerability allows an unauthenticated remote attacker to force the server's UDP receive worker into an unrecoverable infinite loop. The attack requires sending a single crafted control-channel parameter message, immediately followed by a specific 16-byte UDP datagram.\u003c/p\u003e\n\u003cp\u003eOnce triggered, the affected per-stream receive thread enters a state of approximately 100% CPU usage. Because the process stops responding to standard control-channel termination signals, the server becomes permanently unusable for new connections or existing streams until the process is manually terminated using a SIGKILL signal. This issue is particularly impactful for network performance monitoring infrastructure that relies on iperf3 for capacity testing. Defenders should upgrade to iperf3 version 3.22 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a complete service denial for the targeted iperf3 instance. Because the process enters a hang state that does not respond to standard signals, recovery requires manual administrative intervention (SIGKILL). This impacts all network sectors and environments utilizing iperf3 for throughput testing and network diagnostic verification.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of iperf3 to version 3.22 or later to remediate CVE-2026-102253.\u003c/li\u003e\n\u003cli\u003eImplement network-level access control lists (ACLs) to restrict access to the iperf3 control channel (default port 5201) to authorized management subnets only.\u003c/li\u003e\n\u003cli\u003eMonitor server CPU utilization for prolonged spikes reaching 100% on a single thread associated with the iperf3 process name as an indicator of an active DoS event.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T20:52:12Z","date_published":"2026-09-29T22:29:50Z","id":"https://feed.craftedsignal.io/briefs/2026-09-iperf3-dos/","summary":"An unauthenticated remote attacker can trigger a permanent 100% CPU utilization loop in iperf3 versions prior to 3.22 by sending a crafted control-channel message followed by a specific UDP datagram.","title":"Denial of Service Vulnerability in iperf3","url":"https://feed.craftedsignal.io/briefs/2026-09-iperf3-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Iperf3 (\u003c 3.22)","version":"https://jsonfeed.org/version/1.1"}