ALAS2023-2025-1197


Amazon Linux 2023 Security Advisory: ALAS2023-2025-1197
Advisory Released Date: 2025-09-29
Advisory Updated Date: 2025-09-29
Severity: Medium

Issue Overview:

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow. (CVE-2025-54349)

In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt. (CVE-2025-54350)


Affected Packages:

iperf3


Issue Correction:
Run dnf update iperf3 --releasever 2023.9.20250929 or dnf update --advisory ALAS2023-2025-1197 --releasever 2023.9.20250929 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    iperf3-debugsource-3.19.1-1.amzn2023.aarch64
    iperf3-devel-3.19.1-1.amzn2023.aarch64
    iperf3-debuginfo-3.19.1-1.amzn2023.aarch64
    iperf3-3.19.1-1.amzn2023.aarch64

src:
    iperf3-3.19.1-1.amzn2023.src

x86_64:
    iperf3-devel-3.19.1-1.amzn2023.x86_64
    iperf3-debugsource-3.19.1-1.amzn2023.x86_64
    iperf3-debuginfo-3.19.1-1.amzn2023.x86_64
    iperf3-3.19.1-1.amzn2023.x86_64