Back to Security Advisories

[ALSA-2026:61389] Important: iperf3 security update

Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss. Security Fix(es): * iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource ex…

High
AlmaLinux 10 AlmaLinux 9

Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.

Security Fix(es):

* iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource ex…

[ALSA-2026:61389] Important: iperf3 security update

Type:
security

Severity:
important

Release date:
2026-09-01

Description:
Iperf is a tool which can measure maximum TCP bandwidth and tune various parameters and UDP characteristics. Iperf reports bandwidth, delay jitter, and data-gram loss.

Security Fix(es):

* iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion (CVE-2026-71217)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 iperf3-3.9-17.el9_8.1.aarch64.rpm 1e00b4db02072a7b5f28bf89b5140364cbb913178bc7f6679c483869aea04380
i686 iperf3-3.9-17.el9_8.1.i686.rpm c08d9e817740e2a30973c88f863e2a324bd67c24ca57f74169d41c8c8280df16
ppc64le iperf3-3.9-17.el9_8.1.ppc64le.rpm e3ad081e235bc40efa889ac446c88c52d8dca165d6dde88a13fa5ed20fd6c8ae
s390x iperf3-3.9-17.el9_8.1.s390x.rpm 1937f958550581adab8d5718b0a836b4c631afcc04052862a4a9d2f089e9537e
x86_64 iperf3-3.9-17.el9_8.1.x86_64.rpm 1d0e1ea10a800eab748d3a948b09cb8ce7e2201a4b87240b9edcbeac93b7924f

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System