Information Exposure Through Timing Discrepancy in iperf - CVE-2024-26306
Published: May 27, 2024
Vulnerability identifier: #VU89836
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26306
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a timing side channel in RSA decryption operations. A remote attacker can send a large number of messages for decryption and recover credentials.
Affected software
iperf
Oracle Solaris
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
iperf3 (Ubuntu package)
iperf3
iperf3 (Red Hat package)
iperf3-debugsource
iperf3-help
iperf3-devel
iperf3-debuginfo
iperf-debugsource
iperf
libiperf0
iperf-devel
iperf-debuginfo
libiperf0-debuginfo
Oracle Solaris
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
iperf3 (Ubuntu package)
iperf3
iperf3 (Red Hat package)
iperf3-debugsource
iperf3-help
iperf3-devel
iperf3-debuginfo
iperf-debugsource
iperf
libiperf0
iperf-devel
iperf-debuginfo
libiperf0-debuginfo
How to mitigate CVE-2024-26306
Install updates from vendor's website.
iperf - update to 3.17
Oracle Solaris - update to 11.4 SRU 71
iperf3 (Ubuntu package) - addressed in versions 3.7-3ubuntu0.1~esm2, 3.9-1+deb11u1ubuntu0.1, 3.16-1ubuntu0.1~esm1, 3.18-2ubuntu0.1
iperf3 - update to 3.9-13
iperf3 (Red Hat package) - update to 3.9-13.el9
iperf3-debugsource - update to 3.16-3
iperf3-help - update to 3.16-3
iperf3-devel - update to 3.16-3
iperf3-debuginfo - update to 3.16-3
iperf3 - update to 3.16-3
iperf-debugsource - update to 3.17.1-150000.3.9.1
iperf - update to 3.17.1-150000.3.9.1
libiperf0 - update to 3.17.1-150000.3.9.1
iperf-devel - update to 3.17.1-150000.3.9.1
iperf-debuginfo - update to 3.17.1-150000.3.9.1
libiperf0-debuginfo - update to 3.17.1-150000.3.9.1
Oracle Solaris - update to 11.4 SRU 71
iperf3 (Ubuntu package) - addressed in versions 3.7-3ubuntu0.1~esm2, 3.9-1+deb11u1ubuntu0.1, 3.16-1ubuntu0.1~esm1, 3.18-2ubuntu0.1
iperf3 - update to 3.9-13
iperf3 (Red Hat package) - update to 3.9-13.el9
iperf3-debugsource - update to 3.16-3
iperf3-help - update to 3.16-3
iperf3-devel - update to 3.16-3
iperf3-debuginfo - update to 3.16-3
iperf3 - update to 3.16-3
iperf-debugsource - update to 3.17.1-150000.3.9.1
iperf - update to 3.17.1-150000.3.9.1
libiperf0 - update to 3.17.1-150000.3.9.1
iperf-devel - update to 3.17.1-150000.3.9.1
iperf-debuginfo - update to 3.17.1-150000.3.9.1
libiperf0-debuginfo - update to 3.17.1-150000.3.9.1
External References
Related Security Bulletins
- Marvin attack in iPerf
- openEuler update for iperf3
- openEuler 22.03 LTS SP2 update for iperf3
- openEuler 20.03 LTS SP4 update for iperf3
- SUSE update for iperf
- openEuler 24.03 LTS update for iperf3
- Multiple vulnerabilities in Oracle Linux
- Oracle Solaris update for thrid-party components
- Red Hat Enterprise Linux 9 update for iperf3
- Anolis OS update for iperf3
- Ubuntu update for iperf3