CVE-2021-3716 describes a flaw in nbdkit, affecting nbdkit_project and Red Hat Enterprise Linux, where plaintext state is improperly cached across the STARTTLS encryption boundary. A Man-in-the-Middle (MitM) attacker could exploit this by injecting a plaintext NBD_OPT_STRUCTURED_REPLY, potentially causing the client to terminate the NBD session. This vulnerability has a low CVSS score of 3.1, indicating a low availability impact, high attack complexity, and no confidentiality or integrity impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.11.8, < 1.24.6CPE matchmatch criteria | cpe:2.3:a:nbdkit_project:nbdkit:*:*:*:*:*:*:*:* | ||
>= 1.25.1, < 1.26.5CPE matchmatch criteria | cpe:2.3:a:nbdkit_project:nbdkit:*:*:*:*:*:*:*:* | ||
>= 1.27.1, < 1.27.6CPE matchmatch criteria | cpe:2.3:a:nbdkit_project:nbdkit:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.
Mar 8, 2022nbdkit: NBD_OPT_STRUCTURED_REPLY injection on STARTTLS
Aug 16, 2021