cbcvebase.
CVE-2025-54351
published 2025-08-03

CVE-2025-54351: In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

PriorityP353critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.40%
32.0th percentile
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

Affected

7 ranges
VendorProductVersion rangeFixed in
debianiperf3
esiperf3< 3.19.13.19.1
esiperf3
esiperf3>= 0 < 3.19.1-r03.19.1-r0
esiperf3>= 0 < 3.19.1-r03.19.1-r0
msrcazl3_iperf3_3.17.1-2_on_azure_linux_3.0
msrccbl2_iperf3_3.18-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
osv10.0CRITICAL
vendor_debian8.9LOW
vendor_msrc8.9HIGH
vendor_redhat8.9HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.