iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-835"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102253.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "3.14"
},
{
"fixed": "3.22"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "3.14"
},
{
"fixed": "3.22"
}
],
"source": "CPE_FIELD"
}
]
}