If the iperf3 server is running with --rsa-private-key-path option, the user authentication API can be attacked.
CVE is now Public: https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.asc https://github.com/esnet/iperf/releases/tag/3.17 https://nvd.nist.gov/vuln/detail/CVE-2024-26306
Created iperf3 tracking bugs for this issue: Affects: fedora-all [bug 2280519]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:4241 https://access.redhat.com/errata/RHSA-2024:4241
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9185 https://access.redhat.com/errata/RHSA-2024:9185