CyberRota Analysis
AI-GeneratedA pre-authentication heap buffer overflow vulnerability in iperf3 versions 3.20 to 3.21 allows unauthenticated attackers to exploit the decrypt_rsa_message() function by sending oversized ciphertext, potentially leading to arbitrary code execution. Organizations using these versions should prioritize patching to version 3.22 to mitigate the risk of exploitation, given the critical severity rating of 9.2. Immediate action is essential for any systems relying on iperf3 for network performance testing.
Original NVD Description
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22