{"id":"AZL-105492","summary":"CVE-2026-101276 affecting package iperf3 3.17.1-6","details":"iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.","modified":"2026-10-05T05:34:30Z","published":"2026-09-30T21:16:54Z","upstream":["CVE-2026-101276"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101276"}],"affected":[{"package":{"name":"iperf3","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/iperf3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.17.1-6"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105492.json"}}],"schema_version":"1.9.0"}