UbuntuUpdates.org

Package "iperf3"

Name: iperf3

Description:

Internet Protocol bandwidth measuring tool

Latest version: 3.18-2ubuntu0.1
Release: questing (25.10)
Level: security
Repository: universe
Homepage: http://software.es.net/iperf/

Links


Download "iperf3"


Other versions of "iperf3" in Questing

Repository Area Version
base universe 3.18-2
updates universe 3.18-2ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.18-2ubuntu0.1 2026-01-21 12:07:42 UTC

  iperf3 (3.18-2ubuntu0.1) questing-security; urgency=medium

  * SECURITY UPDATE: Heap based buffer overflow
    - debian/patches/CVE-2025-54349.patch: fix off-by-one heap overflow
      in src/iperf_auth.c by allocating additional byte for null terminator
    - CVE-2025-54349

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2025-54350.patch: remove assertion that could
      cause crashes on malformed authentication attempts
    - CVE-2025-54350

  * debian/patches/fix-auth-tests.patch: fix FTBFS by resolving issue with
    openssl 3.5.3 encrypt

 -- Shishir Subedi <email address hidden> Mon, 19 Jan 2026 20:02:23 +0545

CVE-2025-54349 In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
CVE-2025-54350 In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.



About   -   Send Feedback to @ubuntu_updates