Resource management error in iperf - CVE-2023-7250
Published: October 18, 2023 / Updated: July 18, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application. A remote malicious client can initiate the connection with the server sending it less data than expected and block the iperf server from servicing other clients.
Affected software
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
openEuler
Ubuntu
Fedora
libiperf0 (Ubuntu package)
iperf3 (Ubuntu package)
iperf3
iperf3 (Red Hat package)
iperf3-devel
iperf3-debugsource
iperf3-debuginfo
iperf3-help
PowerScale OneFS
How to mitigate CVE-2023-7250
libiperf0 (Ubuntu package) - update to Ubuntu Pro
iperf3 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.7-3ubuntu0.1~esm2, 3.9-1+deb11u1ubuntu0.1, 3.16-1ubuntu0.1~esm1, 3.18-2ubuntu0.1
iperf3 - update to 3.9-13
iperf3 (Red Hat package) - update to 3.9-13.el9
iperf3 - update to 3.15-1.fc40
iperf3 - update to 3.16-1
iperf3-devel - update to 3.16-1
iperf3-debugsource - update to 3.16-1
iperf3-debuginfo - update to 3.16-1
iperf3-help - update to 3.16-1
PowerScale OneFS - addressed in versions 9.4.0.19, 9.5.1.0, 9.5.1.1, 9.7.1.2, 9.9.0.0