Impact
A flaw in iperf3 allows a remote attacker to send crafted control‑channel JSON with oversized numeric parameters such as parallel and len. Those parameters are not properly validated by the server, leading to the creation of excessive streams, threads and large buffers. The resulting resource exhaustion can render the iperf3 process unresponsive or crash it entirely, causing a denial of service for legitimate users.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 7, 8, 9 and 10 running iperf3. No specific iperf3 version information is provided in the advisory, but any instance of iperf3 available in the listed RHEL releases is potentially affected.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high‑severity vulnerability, however the EPSS score is not available, so the assessed exploitation probability is uncertain. The vulnerability is not cataloged in the CISA KEV database. Attackers can exploit the flaw from any network location that can reach the iperf3 server, making the realistic attack vector a remote network‑based DoS.
OpenCVE Enrichment