<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-102253 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-102253/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:29:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-102253/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in iperf3</title><link>https://feed.craftedsignal.io/briefs/2026-09-iperf3-dos/</link><pubDate>Tue, 29 Sep 2026 22:29:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-iperf3-dos/</guid><description>An unauthenticated remote attacker can trigger a permanent 100% CPU utilization loop in iperf3 versions prior to 3.22 by sending a crafted control-channel message followed by a specific UDP datagram.</description><content:encoded><![CDATA[<p>iperf3 versions prior to 3.22 contain a critical denial of service (DoS) vulnerability, tracked as CVE-2026-102253. The vulnerability allows an unauthenticated remote attacker to force the server's UDP receive worker into an unrecoverable infinite loop. The attack requires sending a single crafted control-channel parameter message, immediately followed by a specific 16-byte UDP datagram.</p>
<p>Once triggered, the affected per-stream receive thread enters a state of approximately 100% CPU usage. Because the process stops responding to standard control-channel termination signals, the server becomes permanently unusable for new connections or existing streams until the process is manually terminated using a SIGKILL signal. This issue is particularly impactful for network performance monitoring infrastructure that relies on iperf3 for capacity testing. Defenders should upgrade to iperf3 version 3.22 or later to mitigate this risk.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in a complete service denial for the targeted iperf3 instance. Because the process enters a hang state that does not respond to standard signals, recovery requires manual administrative intervention (SIGKILL). This impacts all network sectors and environments utilizing iperf3 for throughput testing and network diagnostic verification.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of iperf3 to version 3.22 or later to remediate CVE-2026-102253.</li>
<li>Implement network-level access control lists (ACLs) to restrict access to the iperf3 control channel (default port 5201) to authorized management subnets only.</li>
<li>Monitor server CPU utilization for prolonged spikes reaching 100% on a single thread associated with the iperf3 process name as an indicator of an active DoS event.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>network-security</category><category>cve-2026-102253</category></item></channel></rss>