Debian Package Tracker
Register | Log in
Subscribe

iperf3

Internet Protocol bandwidth measuring tool

Choose email to subscribe with

general
  • source: iperf3 (main)
  • version: 3.22-0.1
  • maintainer: Roberto Lumbreras (DMD)
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.9-1+deb11u1
  • o-o-sec: 3.9-1+deb11u3
  • oldstable: 3.12-1+deb12u2
  • old-sec: 3.12-1+deb12u1
  • stable: 3.18-2+deb13u2
  • testing: 3.20-2.1
  • unstable: 3.22-0.1
versioned links
  • 3.9-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.9-1+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.12-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.12-1+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.18-2+deb13u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.20-2.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.22-0.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • iperf3
  • libiperf-dev
  • libiperf0
action needed
4 security issues in forky high

There are 4 open security issues in forky.

4 important issues:
  • CVE-2026-71217: A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.
  • CVE-2026-101276: iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.
  • CVE-2026-101283: iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
  • CVE-2026-102253: iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.
Created: 2026-08-12 Last update: 2026-10-03 05:00
lintian reports 1 error high
Lintian reports 1 error about this package. You should make the package lintian clean getting rid of them.
Created: 2026-10-02 Last update: 2026-10-02 22:31
The VCS repository is not up to date, push the missing commits. high
vcswatch reports that the current version of the package is not in its VCS.
Either you need to push your commits and/or your tags, or the information about the package's VCS are out of date. A common cause of the latter issue when using the Git VCS is not specifying the correct branch when the packaging is not in the default one (remote HEAD branch), which is usually "master" but can be modified in salsa.debian.org in the project's general settings with the "Default Branch" field). Alternatively the Vcs-Git field in debian/control can contain a "-b <branch-name>" suffix to indicate what branch is used for the Debian packaging.
Created: 2026-10-02 Last update: 2026-10-02 15:30
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 2-day delay is over. Check why.
Created: 2026-10-04 Last update: 2026-10-04 22:49
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2026-10-02 Last update: 2026-10-02 15:30
4 low-priority security issues in trixie low

There are 4 open security issues in trixie.

4 issues left for the package maintainer to handle:
  • CVE-2026-71217: (needs triaging) A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.
  • CVE-2026-101276: (needs triaging) iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.
  • CVE-2026-101283: (needs triaging) iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
  • CVE-2026-102253: (needs triaging) iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-08-12 Last update: 2026-10-03 05:00
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 3.22-0.1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-10-02 18:31
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migration status for iperf3 (3.20-2.1 to 3.22-0.1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for ocserv/1.5.0-1: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻, armhf: No tests, superficial or marked flaky ♻, i386: No tests, superficial or marked flaky ♻, ppc64el: No tests, superficial or marked flaky ♻, riscv64: Test triggered, s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Autopkgtest for rtc-testbench/5.5-1: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻, armhf: No tests, superficial or marked flaky ♻, i386: No tests, superficial or marked flaky ♻, ppc64el: No tests, superficial or marked flaky ♻, riscv64: Test triggered, s390x: No tests, superficial or marked flaky ♻ (reference ♻)
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/i/iperf3.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ 3 days old (needed 2 days)
    • Not considered
news
[rss feed]
  • [2026-10-02] Accepted iperf3 3.22-0.1 (source) into unstable (Daniel Baumann)
  • [2026-04-21] iperf3 3.20-2.1 MIGRATED to testing (Debian testing watch)
  • [2026-04-15] Accepted iperf3 3.20-2.1 (source) into unstable (Andreas Tille)
  • [2025-12-20] Accepted iperf3 3.18-2+deb13u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Roberto Lumbreras)
  • [2025-11-26] iperf3 3.20-2 MIGRATED to testing (Debian testing watch)
  • [2025-11-16] Accepted iperf3 3.20-2 (source) into unstable (Roberto Lumbreras)
  • [2025-11-15] Accepted iperf3 3.20-1 (source) into unstable (Roberto Lumbreras)
  • [2025-11-11] Accepted iperf3 3.19.1-2 (source) into unstable (Roberto Lumbreras)
  • [2025-08-31] Accepted iperf3 3.12-1+deb12u2 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Roberto Lumbreras)
  • [2025-08-31] Accepted iperf3 3.18-2+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Roberto Lumbreras)
  • [2025-08-24] Accepted iperf3 3.9-1+deb11u3 (source) into oldoldstable-security (Roberto Lumbreras) (signed by: Adrian Bunk)
  • [2025-08-13] iperf3 3.19.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-04] Accepted iperf3 3.19.1-1 (source) into unstable (Roberto Lumbreras)
  • [2025-03-06] iperf3 3.18-2 MIGRATED to testing (Debian testing watch)
  • [2025-02-24] Accepted iperf3 3.18-2 (source) into unstable (Roberto Lumbreras)
  • [2025-01-28] Accepted iperf3 3.9-1+deb11u2 (source) into oldstable-security (Markus Koschany)
  • [2025-01-01] iperf3 3.18-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-27] Accepted iperf3 3.18-1 (source) into unstable (Roberto Lumbreras)
  • [2024-06-02] iperf3 3.17.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-27] Accepted iperf3 3.17.1-1 (source) into unstable (Roberto Lumbreras)
  • [2024-02-08] iperf3 3.16-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-29] Accepted iperf3 3.16-1 (source) into unstable (Roberto Lumbreras)
  • [2023-10-27] iperf3 3.15-1 MIGRATED to testing (Debian testing watch)
  • [2023-10-16] Accepted iperf3 3.15-1 (source) into unstable (Roberto Lumbreras)
  • [2023-07-25] Accepted iperf3 3.6-2+deb10u1 (source) into oldoldstable (Markus Koschany)
  • [2023-07-22] Accepted iperf3 3.9-1+deb11u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Aron Xu)
  • [2023-07-22] Accepted iperf3 3.12-1+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Aron Xu)
  • [2023-07-17] Accepted iperf3 3.12-1+deb12u1 (source) into stable-security (Debian FTP Masters) (signed by: Aron Xu)
  • [2023-07-17] Accepted iperf3 3.9-1+deb11u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Aron Xu)
  • [2023-07-14] iperf3 3.14-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (1, 0)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (100, -)
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.20-2.1build1
  • 2 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing