CVE-2024-53580
published 2024-12-18CVE-2024-53580: iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.92%
56.3th percentile
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | iperf3 | < iperf3 3.9-1+deb11u2 (bullseye) | iperf3 3.9-1+deb11u2 (bullseye) |
| es | iperf3 | — | — |
| es | iperf3 | >= 0 < 3.9-1+deb11u2 | 3.9-1+deb11u2 |
| es | iperf3 | >= 0 < 3.18-1 | 3.18-1 |
| es | iperf3 | >= 0 < 3.18-1 | 3.18-1 |
| es | iperf3 | >= 0 < 3.9-1+deb11u1ubuntu0.1 | 3.9-1+deb11u1ubuntu0.1 |
| es | iperf3 | >= 0 < 3.18-2ubuntu0.1 | 3.18-2ubuntu0.1 |
| es | iperf3 | >= 0 < 3.7-3ubuntu0.1~esm2 | 3.7-3ubuntu0.1~esm2 |
| es | iperf3 | >= 0 < 3.16-1ubuntu0.1~esm1 | 3.16-1ubuntu0.1~esm1 |
| msrc | azl3_iperf3_3.17.1-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_iperf3_3.17-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_iperf3_3.18-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
iperf3 vulnerabilities
vendor_ubuntu·2026-01-21·CVSS 5.3
CVE-2024-26306 [MEDIUM] iperf3 vulnerabilities
Title: iperf3 vulnerabilities
Summary: Several security issues were fixed in iperf3.
Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. This issue was only addressed in
Ubuntu 22.04 LTS. (CVE-2023-7250)
It was discovered that iperf3 had a timing side-channel when performing RSA
decryption. An attacker could possibly use this issue to recover sensitive
information. This issue was only addressed in Ubuntu 20.04 LTS and Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-26306)
It was discovered that iperf3 incorrectly handled certain inputs. An
attacker could possibly use this issue
Red Hat
iperf: Denial of Service in iperf Due to Improper JSON Handling
vendor_redhat·2024-12-18·CVSS 7.5
CVE-2024-53580 [HIGH] CWE-476 iperf: Denial of Service in iperf Due to Improper JSON Handling
iperf: Denial of Service in iperf Due to Improper JSON Handling
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
A flaw was found in iperf. This vulnerability allows a Denial of Service (DoS) via the injection of malformed JSON data, which can result in a segmentation fault when a NULL pointer is passed to strdup().
Statement: This vulnerability marked as important severity rather than moderate due to its potential to cause a complete denial of service (DoS) by exploiting a segmentation fault through malformed JSON data. The flaw stems from improper input validation, which allows attackers to crash the server by sending invalid data that triggers memory mismanagement. Since iperf is widely used in performance testing of netwo
Microsoft
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
vendor_msrc·2024-12-10·CVSS 7.5
CVE-2024-53580 [HIGH] CWE-476 iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Reme
Debian
CVE-2024-53580: iperf3 - iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_e...
vendor_debian·2024·CVSS 7.5
CVE-2024-53580 [HIGH] CVE-2024-53580: iperf3 - iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_e...
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.9-1+deb11u2)
forky: resolved (fixed in 3.18-1)
sid: resolved (fixed in 3.18-1)
trixie: resolved (fixed in 3.18-1)
OSV
iperf3 vulnerabilities
osv·2026-01-21·CVSS 5.3
CVE-2023-7250 [MEDIUM] iperf3 vulnerabilities
iperf3 vulnerabilities
Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. This issue was only addressed in
Ubuntu 22.04 LTS. (CVE-2023-7250)
It was discovered that iperf3 had a timing side-channel when performing RSA
decryption. An attacker could possibly use this issue to recover sensitive
information. This issue was only addressed in Ubuntu 20.04 LTS and Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-26306)
It was discovered that iperf3 incorrectly handled certain inputs. An
attacker could possibly use this issue to cause a denial of service. This
issue was only addressed in
GHSA
GHSA-2w89-5px3-fvx6: iperf v3
ghsa_unreviewed·2024-12-19
CVE-2024-53580 GHSA-2w89-5px3-fvx6: iperf v3
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
OSV
CVE-2024-53580: iperf v3
osv·2024-12-18·CVSS 7.5
CVE-2024-53580 [HIGH] CVE-2024-53580: iperf v3
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
No detection rules found.
No public exploits indexed.
2024-12-18
Published