Resource management error in iperf - CVE-2023-7250

 

Resource management error in iperf - CVE-2023-7250

Published: October 18, 2023 / Updated: July 18, 2024


Vulnerability identifier: #VU82202
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-7250
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application. A remote malicious client can initiate the connection with the server sending it less data than expected and block the iperf server from servicing other clients.


Affected software

iperf
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
openEuler
Ubuntu
Fedora
libiperf0 (Ubuntu package)
iperf3 (Ubuntu package)
iperf3
iperf3 (Red Hat package)
iperf3-devel
iperf3-debugsource
iperf3-debuginfo
iperf3-help
PowerScale OneFS

How to mitigate CVE-2023-7250

Install updates from vendor's website.

iperf - update to 3.15
libiperf0 (Ubuntu package) - update to Ubuntu Pro
iperf3 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.7-3ubuntu0.1~esm2, 3.9-1+deb11u1ubuntu0.1, 3.16-1ubuntu0.1~esm1, 3.18-2ubuntu0.1
iperf3 - update to 3.9-13
iperf3 (Red Hat package) - update to 3.9-13.el9
iperf3 - update to 3.15-1.fc40
iperf3 - update to 3.16-1
iperf3-devel - update to 3.16-1
iperf3-debugsource - update to 3.16-1
iperf3-debuginfo - update to 3.16-1
iperf3-help - update to 3.16-1
PowerScale OneFS - addressed in versions 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0

External References

Related Security Bulletins