Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE Leap 15.6: iperf Important Buffer Overflow CVE-2025-54351

opensuse
Calendar Grey August 11, 2025
Dist Opensuse Esm H88
A critical security patch for iperf has been released, targeting various issues in openSUSE Leap 15.6.
An update that solves three vulnerabilities can now be installed.

Description

This update for iperf fixes the following issues:

* update to 3.19.1:

* CVE-2025-54351: Fixed buffer overflow in net.c (bsc#1247522)

* CVE-2025-54350: Fixed Base64Decode assertion failure and application exit

upon a malformed authentication attempt (bsc#1247520)

* CVE-2025-54349: Fixed off-by-one error and resultant heap-based buffer

overflow (bsc#1247519)

* update to 3.19:

* iperf3 now supports the use of Multi-Path TCP (MPTCPv1) on Linux with the

use of the `-m` or `--mptcp` flag. (PR #1661)

* iperf3 now supports a `--cntl-ka` option to enable TCP keepalives on the

control connection. (#812, #835, PR #1423)

* iperf3 now supports the `MSG_TRUNC` receive option, specified by the

`--skip-rx-copy`. This theoretically improves the rated throughput of tests

at high bitrates by not delivering network payload data to userspace.

(#1678, PR #1717)

* A bug that caused the bitrate setting to be ignored when bursts are set, has

been fixed....

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Package Hub 15 15-SP7

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-2749=1

* SUSE Enterprise Storage 7.1

zypper in -t patch SUSE-Storage-7.1-2025-2749=1

* openSUSE Leap 15.6

zypper in -t patch openSUSE-SLE-15.6-2025-2749=1

* SUSE Package Hub 15 15-SP6

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-2749=1

Package List

* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)

* iperf-3.19.1-150000.3.15.1

* libiperf0-debuginfo-3.19.1-150000.3.15.1

* iperf-devel-3.19.1-150000.3.15.1

* iperf-debuginfo-3.19.1-150000.3.15.1

* libiperf0-3.19.1-150000.3.15.1

* iperf-debugsource-3.19.1-150000.3.15.1

* SUSE Enterprise Storage 7.1 (aarch64 x86_64)

* iperf-3.19.1-150000.3.15.1

* libiperf0-debuginfo-3.19.1-150000.3.15.1

* iperf-debuginfo-3.19.1-150000.3.15.1

* libiperf0-3.19.1-150000.3.15.1

* iperf-debugsource-3.19.1-150000.3.15.1

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)

* iperf-3.19.1-150000.3.15.1

* libiperf0-debuginfo-3.19.1-150000.3.15.1

* iperf-devel-3.19.1-150000.3.15.1

* iperf-debuginfo-3.19.1-150000.3.15.1

* libiperf0-3.19.1-150000.3.15.1

* iperf-debugsource-3.19.1-150000.3.15.1

* SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64)

* iperf-3.19.1-150000.3.15.1

* libiperf0-debuginfo-3.19.1-150000.3.15.1

* iperf-devel-3.19.1-150000.3.15.1

* iperf-debuginfo-3.19.1-150000.3.15.1

* libiperf0-3.19.1-150000.3.15.1

*...

Read the Full Advisory

References

* bsc#1247519

* bsc#1247520

* bsc#1247522

## References:

* https://www.suse.com/security/cve/CVE-2025-54349.html

* https://www.suse.com/security/cve/CVE-2025-54350.html

* https://www.suse.com/security/cve/CVE-2025-54351.html

* https://bugzilla.suse.com/show_bug.cgi?id=1247519

* https://bugzilla.suse.com/show_bug.cgi?id=1247520

* https://bugzilla.suse.com/show_bug.cgi?id=1247522

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:02749-1
Release Date: 2025-08-11T07:06:51Z
Affected Products: * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here