@thomrstrom I became aware of the CVE yesterday when a ticket was opened about it in Fedora. I'm a maintainer of the Fedora package so I immediately checked if AlmaLinux/RHEL were vulnerable too and proceeded from there.
My PR has been rejected by RH and I'm not terribly sure why. At least I tried, I guess, and since AlmaLinux isn't targeting 1:1 we have the patch and RHEL won't I suppose.
https://gitlab.com/redhat/centos-stream/rpms/iperf3/-/merge_requests/5#note_1476778724