CVE-2025-54349

Name
CVE-2025-54349
Description
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/esnet/iperf/commit/4e5313bab0b9b3fe03513ab54f722c8a3e4b7bdf
cve@mitre.org https://github.com/esnet/iperf/releases/tag/3.19.1
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/08/msg00020.html

Match rules

CPE URI Source package Min version Max version
iperf3 >= 0 < 3.19.1
cpe:2.3:a:es:iperf3:*:*:*:*:*:*:*:* iperf3 >= 3.2 < 3.19.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
iperf3 edge-main 3.19.1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
iperf3 edge-main 3.19-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
iperf3 edge-main 3.18-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
iperf3 edge-main 3.17.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
iperf3 3.22-main 3.19.1-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
iperf3 3.22-main 3.19-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
iperf3 3.21-main 3.17.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
iperf3 3.20-main 3.17.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
iperf3 3.19-main 3.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable