Logo
vulnerabilityCVE-2024-26306
Name
CVE-2024-26306
Source
NVD ( link)Debian ( link)
Description
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
iperf3
Patched

Vulnerability Ratings#


5.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.18
Not Affected
buildroot
master
3.21
Not Affected
openwrt
master
3.21-r2
Not Affected
openwrt
openwrt-25.12
3.20-r1
Not Affected
yocto
master
3.21
Not Affected
yocto
scarthgap
3.18
Not Affected

Resolved with patches#


iperf3 (yocto:kirkstone)

#
Title
Author
Resolve
1
Using OAEP padding instead of PKCS1 padding for OpenSSL. Fix
Sarah Larsen <swlarsen@Sarahs-MBP.lan>
CVE-2024-26306