CyberRota Analysis
AI-GeneratedIperf3 versions prior to 3.22 are vulnerable to a denial of service attack that allows unauthenticated remote attackers to crash the server's UDP receive worker into an infinite loop, leading to sustained high CPU usage. This vulnerability can render the server inoperable until it is forcibly terminated, as it does not respond to standard control-channel closure commands. Organizations using iperf3 for network performance testing should prioritize patching to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.