CVE-2023-38403: Apple macOS

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

Affected products

  • Apple macOS: before 13.6.1 (fixed in 13.6.1); version 14.0 only
  • Debian Debian Linux: version 10.0 only
  • Es IPERF3: before 3.14 (fixed in 3.14)
  • Fedoraproject Fedora: version 37 only; version 38 only
  • Netapp Clustered Data Ontap: version 9.0 only
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified

Published 2023-07-17. Last modified 2026-06-17.