CyberRota Analysis
AI-GeneratedA critical vulnerability in iperf3 version 3.21 allows remote, unauthenticated attackers to exploit a heap use-after-free condition, potentially leading to arbitrary code execution. This occurs when the server's watchdog function frees streams without properly managing associated worker threads, resulting in dereferencing freed memory. Organizations using iperf3 for network performance testing should prioritize upgrading to version 3.22 to mitigate this risk.
Original NVD Description
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.