Vulnerability Description
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
CVSS Score
8.9
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Es | Iperf3 | 3.19 |
Related Weaknesses (CWE)
References
- https://github.com/esnet/iperf/commit/969b7f70c447513e92c9798f22e82b40ebc53bf0Patch
- https://github.com/esnet/iperf/releases/tag/3.19.1Release Notes
FAQ
What is CVE-2025-54351?
CVE-2025-54351 is a vulnerability with a CVSS score of 8.9 (HIGH). In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
How severe is CVE-2025-54351?
CVE-2025-54351 has been rated HIGH with a CVSS base score of 8.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54351?
Check the references section above for vendor advisories and patch information. Affected products include: Es Iperf3.