Reachable assertion in iperf - CVE-2025-54350

 

Reachable assertion in iperf - CVE-2025-54350

Published: August 12, 2025


Vulnerability identifier: #VU113837
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54350
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion in iperf_auth.c. A remote attacker can perform a denial of service (DoS) attack.


Affected software

iperf
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Enterprise Storage
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
Anolis OS
iperf3 (Ubuntu package)
iperf3-debuginfo
iperf3
iperf3-debugsource
iperf3-devel
iperf3-help
iperf3-doc
iperf-debugsource
libiperf0
iperf-debuginfo
iperf-devel
libiperf0-debuginfo
iperf

How to mitigate CVE-2025-54350

Install updates from vendor's website.

iperf - update to 3.19.1
iperf3 (Ubuntu package) - addressed in versions 3.7-3ubuntu0.1~esm2, 3.9-1+deb11u1ubuntu0.1, 3.16-1ubuntu0.1~esm1, 3.18-2ubuntu0.1
iperf3-debuginfo - update to 3.18-2
iperf3 - update to 3.18-2
iperf3-debugsource - update to 3.18-2
iperf3-devel - update to 3.18-2
iperf3-help - update to 3.18-2
iperf3 - update to 3.19.1-1
iperf3-doc - update to 3.19.1-1
iperf3-devel - update to 3.19.1-1
iperf-debugsource - update to 3.19.1-150000.3.15.1
libiperf0 - update to 3.19.1-150000.3.15.1
iperf-debuginfo - update to 3.19.1-150000.3.15.1
iperf-devel - update to 3.19.1-150000.3.15.1
libiperf0-debuginfo - update to 3.19.1-150000.3.15.1
iperf - update to 3.19.1-150000.3.15.1

External References

Related Security Bulletins