CVE-2025-54351
published 2025-08-03CVE-2025-54351: In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
PriorityP353critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.40%
32.0th percentile
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | iperf3 | — | — |
| es | iperf3 | < 3.19.1 | 3.19.1 |
| es | iperf3 | — | — |
| es | iperf3 | >= 0 < 3.19.1-r0 | 3.19.1-r0 |
| es | iperf3 | >= 0 < 3.19.1-r0 | 3.19.1-r0 |
| msrc | azl3_iperf3_3.17.1-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_iperf3_3.18-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
osv10.0CRITICAL
vendor_debian8.9LOW
vendor_msrc8.9HIGH
vendor_redhat8.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-54351: In iperf before 3
osv·2025-08-03·CVSS 10.0
CVE-2025-54351 [CRITICAL] CVE-2025-54351: In iperf before 3
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
GHSA
GHSA-xjwm-4pfw-49g2: In iperf before 3
ghsa_unreviewed·2025-08-03
CVE-2025-54351 [HIGH] CWE-420 GHSA-xjwm-4pfw-49g2: In iperf before 3
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
Microsoft
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
vendor_msrc·2025-08-12·CVSS 8.9
CVE-2025-54351 [HIGH] CWE-420 In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Red Hat
iperf3: iperf Buffer Overflow
vendor_redhat·2025-08-03·CVSS 8.9
CVE-2025-54351 [HIGH] CWE-420 iperf3: iperf Buffer Overflow
iperf3: iperf Buffer Overflow
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
A flaw was found in iperf3. The `recv` function in `net.c` exhibits a buffer overflow when the `--skip-rx-copy` option is used with `MSG_TRUNC`, allowing a network attacker to trigger the overflow. This vulnerability allows an attacker to send a specially crafted message. The resulting buffer overflow may lead to an application-level denial of service.
Statement: This vulnerability was introduced with option --skip-rx-copy which was added after version 3.17.1. We currently have an older version of code in Red Hat Enterprise Linux(RHEL). No Red Hat products or offerings are affected by this vulnerability.
This vulnerability marked as Important instead a M
Debian
CVE-2025-54351: iperf3 - In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used ...
vendor_debian·2025·CVSS 8.9
CVE-2025-54351 [HIGH] CVE-2025-54351: iperf3 - In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used ...
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-54351 iperf3: iperf Buffer Overflow [fedora-42]
bugzilla·2025-08-04·CVSS 10.0
CVE-2025-54351 [CRITICAL] CVE-2025-54351 iperf3: iperf Buffer Overflow [fedora-42]
CVE-2025-54351 iperf3: iperf Buffer Overflow [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are
Bugzilla
CVE-2025-54351 iperf3: iperf Buffer Overflow
bugzilla·2025-08-03·CVSS 10.0
CVE-2025-54351 [CRITICAL] CVE-2025-54351 iperf3: iperf Buffer Overflow
CVE-2025-54351 iperf3: iperf Buffer Overflow
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
2025-08-03
Published