Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-3716

16
FAUCET Score

CVE-2021-3716 describes a flaw in nbdkit, affecting nbdkit_project and Red Hat Enterprise Linux, where plaintext state is improperly cached across the STARTTLS encryption boundary. A Man-in-the-Middle (MitM) attacker could exploit this by injecting a plaintext NBD_OPT_STRUCTURED_REPLY, potentially causing the client to terminate the NBD session. This vulnerability has a low CVSS score of 3.1, indicating a low availability impact, high attack complexity, and no confidentiality or integrity impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.11.8, < 1.24.6CPE matchmatch criteria
cpe:2.3:a:nbdkit_project:nbdkit:*:*:*:*:*:*:*:*
>= 1.25.1, < 1.26.5CPE matchmatch criteria
cpe:2.3:a:nbdkit_project:nbdkit:*:*:*:*:*:*:*:*
>= 1.27.1, < 1.27.6CPE matchmatch criteria
cpe:2.3:a:nbdkit_project:nbdkit:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.1LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.58%
Probability of exploitation in next 30 days
EPSS Percentile
44.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0058 is in the 13th percentile among its peer group of 1,637 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: 19647-16823
microsoftpatch availablevia msrc
Product: cbl2 nbdkit on CBL Mariner 2.0
redhatpatch availablevia redhat_api
Product: Advanced Virtualization for RHEL 8.5.0.ZFixed in: virt-devel:av-8050020220115095224.c5368500
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: virt:rhel-8060020220408104655.d63f516d
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: virt-devel:rhel-8060020220408104655.d63f516d
View patch
redhatpatch availablevia redhat_api
Product: Advanced Virtualization for RHEL 8.5.0.ZFixed in: virt:av-8050020220115095224.c5368500
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8 Advanced VirtualizationFixed in: virt:8.2/nbdkit
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8 Advanced VirtualizationFixed in: virt:av/nbdkit

Vendor Advisories (2)

microsoft2022-Mar/CVE-2021-3716Low

A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.

Mar 8, 2022
redhatCVE-2021-3716Low

nbdkit: NBD_OPT_STRUCTURED_REPLY injection on STARTTLS

Aug 16, 2021

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
gitlab.com / nbdkit/nbdkit/-/commit/09a13dafb7bb3a38ab52eb5501cba786365ba7fd
PatchThird Party Advisory
gitlab.com / nbdkit/nbdkit/-/commit/6c5faac6a37077cf2366388a80862bb00616d0d8
PatchThird Party Advisory
listman.redhat.com / archives/libguestfs/2021-August/msg00083.html
Broken Link
openwall.com / lists/oss-security/2021/08/18/2
Mailing ListThird Party Advisory