CVE-2026-102253

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets1 URL
By indicator
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🔴 iperf3'te uzaktan tetiklenebilen DoS açığı CVE-2026-102253 (CVSS: 7.5 (High) için PoC yayınlandı. Bu açık UDP paket boyutu doğrulamasındaki bir hatadan kaynaklanıyor. Özel hazırlanmış kontrol mesajı ve UDP paketiyle alım iş parçacığı sonsuz döngüye sokularak CPU tüketimi artırılabiliyor ve hizmetin kullanılabilirliği engellenebiliyor. Kimlik doğrulama gerektirmiyor. Bu açık 29 Eylül 2026'da 3.22 sürümünde yamalandı, mutlaka güncelleyin. Ayrıca, ağ üzerinden erişilebilen iperf3 servislerinde kontrol portunu güvenilir IP adresleriyle sınırlandırabilirsiniz. https://github.com/Ravi-lk/CVE-2026-102253-POC

    01000195
    2.4K followersView on X

Explore more