Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, restrict network access to the `iperf3` control port, ensuring it is only reachable by trusted clients. This can be achieved by configuring firewall rules to limit inbound connections to the `iperf3` service. Additionally, consider running the `iperf3` service within environments that enforce process or container memory limits to further contain potential resource exhaustion. Note that authentication alone is insufficient as the memory allocation occurs before authentication checks.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 11 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service. | |
| Title | Iperf3: unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-789 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-11T10:20:34.420Z
Reserved: 2026-08-05T08:41:54.899Z
Link: CVE-2026-71218
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-11T10:30:04Z