From patchwork Fri Oct 2 11:23:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 10299 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hx5yF0k0pz3wqG for ; Fri, 02 Oct 2026 11:23:49 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hx5yC33LKz89f for ; Fri, 02 Oct 2026 11:23:47 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hx5y805yBz37Gg for ; Fri, 02 Oct 2026 11:23:44 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hx5y049wfz37CR for ; Fri, 02 Oct 2026 11:23:36 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hx5y02wZDz2q6; Fri, 02 Oct 2026 11:23:36 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1790940216; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=g9q2INyg3Oknzrb/uAwWyc6zwyaTlJl+5bH1cd7Tc4Y=; b=Til7E84riou8v/KRhxaL2p+sS7g11EWRAaMyLq1KpOVk3QbksxXmAQg1OKMK5otLzCfMPb yFKmuPspIfkCoXDQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1790940216; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=g9q2INyg3Oknzrb/uAwWyc6zwyaTlJl+5bH1cd7Tc4Y=; b=lc34pW+r8gOuO5XOkscKSGQnZ3IRzhSOn91EDBpbfQgXzJbpnGC2H/KQNC/gK24iemMysX IRGUyFPcimwSaL5wjZZwerUy3ILkpUkIjEAUL0zrttpNJOhoGayNVFW2JNqmXKnAD4UwA2 OuIrqwRc57mt/WLOZemnXZ2aHg2po0j114nv/nIt5ROg8wd6CuNOFpyOUxCNb2/deiIwMD 8Wv+j6IV1Re76jcPF87P0J+m7kPiQAvqs+eOBx2iJ9aHCuzKOdOX8vpkGkboCNkP+s7YE4 R8IMj8n0ogMgtIB5wXoMIZKoeJYWFDXbKGChc+rmgNxnNtBL0tPsgtcAolka3A== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] iperf3: Update to version 3.22 Date: Fri, 2 Oct 2026 13:23:24 +0200 Message-ID: <20261002112330.3568361-7-adolf.belka@ipfire.org> In-Reply-To: <20261002112330.3568361-1-adolf.belka@ipfire.org> References: <20261002112330.3568361-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 3.21 to 3.22 - No change in rootfile - 4 CVE fixes - Changelog 3.22 * Security notes * Thanks to Claude and Ada Logics for finding and reporting two potential security vulnerabilities. One is a remote use-after-free in iperf_server_api.c (ANT-2026-E5BA80X9 / CVE-2026-101283) and the other is a heap buffer overflow in iperf_auth.c (ANT-2026-FXH14FHV / CVE-2026-101276). * Thanks to Justin Stitt for reporting and fixing a heap-buffer overflow was fixed in iperf_auth.c (PR #2027). * Thanks to Ravindu Lakmina Munaweera (Github: @Ravi-lk) for reporting and fixing a DOS infinite-loop (CVE-2026-102253). * Thanks to Dirk Müller for finding and reporting an issue with test parameters (PR #2039, CVE-2026-71217). * The iperf-3.18 release notes were updated to reflect that a code change in that version addresses CVE-2026-71218. * Notable user-visible changes * Attempting to set zero parallel streams is no longer allowed (PR #2048). * Zerocopy and rx-copy are now allowed in the case of reverse direction tests and the server (sending side) supports these features but the client (receiving side) does not (#2045, PR #2044). * The limit on GSO_MAX_DG_IN_BF was fixed to limit the number of segments to the maximum allowed (#2032 / PR #2033). This change unbreaks GSO for small message sizes. * Notable developer-visible changes * In iperf_auth.c, in addition to fixing the heap buffer overflow, the return value of several functions is checked (PR #2046, PR #2040). * Several file descriptor leaks have been fixed (PR #2034). * In iperf_tcp, connections now timeout to prevent a race condition in accepting new connections to avoid a deadlock (#2029, PR #2030). * Periodic timers are now cancelled at the end of a test (#2018, PR #2021). * DSCP/TOS is now correctly set in the first UDP/TCP stream packet (#510, #830, PR #2047). Signed-off-by: Adolf Belka --- lfs/iperf3 | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/lfs/iperf3 b/lfs/iperf3 index 7c4095ed9..01b0f3252 100644 --- a/lfs/iperf3 +++ b/lfs/iperf3 @@ -26,7 +26,7 @@ include Config SUMMARY = A tool to measure network performance -VER = 3.21 +VER = 3.22 THISAPP = iperf-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE) DIR_APP = $(DIR_SRC)/$(THISAPP) TARGET = $(DIR_INFO)/$(THISAPP) PROG = iperf3 -PAK_VER = 9 +PAK_VER = 10 DEPS = @@ -51,7 +51,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 696a13caaa5cf52a69c65566ae4d2d8788a4225d689d32e73306f5174dad141c92ea3acdda9a929803a1e57eee6844350be2da749e5f44c48bf0ab7890e97745 +$(DL_FILE)_BLAKE2 = 1e06b7faca73002b760dba4bab1349140970daaa427e46a2ac5b96030494b6465e6875d58f550283e608bfcdcea76a13857d3b2d69f46a8bb78cfe0964ee95b2 install : $(TARGET) check : $(patsubst %,$(DIR_CHK)/%,$(objects))