{"id":"AZL-105051","summary":"CVE-2026-102253 affecting package iperf3 3.17.1-6","details":"iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage, rendering the server unusable until forcibly killed with SIGKILL, as the process does not respond to normal control-channel closure.","modified":"2026-09-30T14:18:01.077491718Z","published":"2026-09-29T21:17:13Z","upstream":["CVE-2026-102253"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102253"}],"affected":[{"package":{"name":"iperf3","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/iperf3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.17.1-6"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105051.json"}}],"schema_version":"1.9.0"}