cbcvebase.
CVE-2025-54349
published 2025-08-03

CVE-2025-54349: In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

PriorityP354critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.38%
30.1th percentile
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianiperf3< iperf3 3.12-1+deb12u2 (bookworm)iperf3 3.12-1+deb12u2 (bookworm)
esiperf3< 3.19.13.19.1
esiperf3>= 0 < 3.9-1+deb11u33.9-1+deb11u3
esiperf3>= 0 < 3.12-1+deb12u23.12-1+deb12u2
esiperf3>= 0 < 3.18-2+deb13u13.18-2+deb13u1
esiperf3>= 0 < 3.19.1-13.19.1-1
esiperf3>= 0 < 3.9-1+deb11u1ubuntu0.13.9-1+deb11u1ubuntu0.1
esiperf3>= 0 < 3.18-2ubuntu0.13.18-2ubuntu0.1
esiperf3>= 0 < 3.7-3ubuntu0.1~esm23.7-3ubuntu0.1~esm2
esiperf3>= 0 < 3.16-1ubuntu0.1~esm13.16-1ubuntu0.1~esm1
esiperf3>= 3.2 < 3.19.13.19.1
msrcazl3_iperf3_3.17.1-3_on_azure_linux_3.0
msrccbl2_iperf3_3.18-1_on_cbl_mariner_2.0
msrccbl2_iperf3_3.18-2_on_cbl_mariner_2.0

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
osv10.0CRITICAL
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.