Commit Graph

13 Commits

Author SHA1 Message Date
RHEL Packaging Agent
2c8669efac Fix CVE-2026-71217: add JSON value bounds checks in iperf3
Backport upstream fix (commit 494dd377) for CVE-2026-71217
to iperf3 3.5. The patch adds bounds checking for all
peer-controlled JSON parameters in get_parameters() and
additional bounds checks in iperf_parse_arguments(), preventing
malicious clients/servers from injecting out-of-range values
for parameters such as num_streams, window size, MSS, TOS,
bandwidth, burst, and others.

CVE: CVE-2026-71217
Upstream patches:
 - 494dd377ec.patch
Resolves: RHEL-236174

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-08-12 09:38:03 +00:00
Michal Ruprich
2106674a83 Resolves: RHEL-136175 - iperf Heap Buffer Overflow (CVE-2025-54349) 2026-01-23 10:29:48 +01:00
František Hrdina
88bee09197 Update location of fmf plans 2025-08-11 10:37:33 +02:00
Michal Ruprich
10d9f6dbf5 Resolves: RHEL-72924 - Denial of Service in iperf Due to Improper JSON Handling 2025-01-08 16:58:47 +01:00
Michal Ruprich
c34117a372 Improving testing files 2024-06-14 12:19:29 +02:00
Michal Ruprich
57d25d7381 Resolves: RHEL-29578 - vulnerable to marvin attack if the authentication option is used 2024-06-12 13:27:27 +02:00
Michal Ruprich
e5d9de6fb9 Resolves: RHEL-17069 - possible denial of service 2024-06-04 10:32:08 +02:00
Michal Ruprich
45156ced42 Related: #2222205 - bumping nvr for correct update path 2023-07-28 10:15:04 +02:00
44939d1eb3 Fixes CVE-2023-38403
Resolves rhbz#2223729

Signed-off-by: Jonathan Wright <jonathan@almalinux.org>
2023-07-18 11:52:05 -05:00
Troy Dawson
2be41c8716 Bring gating.yaml over from Brew dist-git
Signed-off-by: Troy Dawson <tdawson@redhat.com>
2023-03-10 10:45:52 -08:00
James Antill
750c4cc247 Import rpm: c8s 2023-02-27 13:43:43 -05:00
James Antill
721dccc30d Auto sync2gitlab import of iperf3-3.5-6.el8.src.rpm 2022-05-26 09:49:59 -04:00
James Antill
9c758e4884 Initial c8s branch. 2022-05-26 09:49:56 -04:00