CVE-2023-7250: Es IPERF3

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.

Affected products

  • Es IPERF3: before 3.15 (fixed in 3.15)
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux For Arm 64: version 8.0_aarch64 only; version 9.0_aarch64 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 8.0_s390x only; version 9.0_s390x only
  • Red Hat Enterprise Linux For Power Little Endian: version 8.0_ppc64le only

Published 2024-03-18. Last modified 2026-06-17.