{"id":"UBUNTU-CVE-2021-3716","details":"A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.","modified":"2026-05-20T16:06:28.689583536Z","published":"2022-03-02T23:15:00Z","upstream":["CVE-2021-3716"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3716"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2021-3716"},{"type":"REPORT","url":"https://listman.redhat.com/archives/libguestfs/2021-August/msg00077.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-3716"}],"affected":[{"package":{"name":"nbdkit","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/nbdkit?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.1.10-1","1.1.11-1","1.1.11-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"nbdkit","binary_version":"1.1.11-1build1"},{"binary_name":"nbdkit-plugin-guestfs","binary_version":"1.1.11-1build1"},{"binary_version":"1.1.11-1build1","binary_name":"nbdkit-plugin-libvirt"},{"binary_name":"nbdkit-plugin-perl","binary_version":"1.1.11-1build1"},{"binary_name":"nbdkit-plugin-python","binary_version":"1.1.11-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3716.json"}},{"package":{"name":"nbdkit","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/nbdkit?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.12.4-1","1.12.4-1build1","1.14.2-3","1.16.1-2","1.16.1-3","1.16.1-3ubuntu1","1.16.2-1ubuntu1","1.16.2-1ubuntu2","1.16.2-1ubuntu3"],"ecosystem_specific":{"binaries":[{"binary_name":"nbdkit","binary_version":"1.16.2-1ubuntu3"},{"binary_version":"1.16.2-1ubuntu3","binary_name":"nbdkit-plugin-guestfs"},{"binary_name":"nbdkit-plugin-libvirt","binary_version":"1.16.2-1ubuntu3"},{"binary_name":"nbdkit-plugin-lua","binary_version":"1.16.2-1ubuntu3"},{"binary_name":"nbdkit-plugin-perl","binary_version":"1.16.2-1ubuntu3"},{"binary_name":"nbdkit-plugin-python","binary_version":"1.16.2-1ubuntu3"},{"binary_version":"1.16.2-1ubuntu3","binary_name":"nbdkit-plugin-ruby"},{"binary_name":"nbdkit-plugin-tcl","binary_version":"1.16.2-1ubuntu3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3716.json"}},{"package":{"name":"nbdkit","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/nbdkit?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.24.1-2ubuntu1","1.24.1-2ubuntu2","1.24.1-2ubuntu3","1.24.1-2ubuntu4"],"ecosystem_specific":{"binaries":[{"binary_name":"nbdkit","binary_version":"1.24.1-2ubuntu4"},{"binary_version":"1.24.1-2ubuntu4","binary_name":"nbdkit-plugin-guestfs"},{"binary_version":"1.24.1-2ubuntu4","binary_name":"nbdkit-plugin-libvirt"},{"binary_name":"nbdkit-plugin-lua","binary_version":"1.24.1-2ubuntu4"},{"binary_name":"nbdkit-plugin-perl","binary_version":"1.24.1-2ubuntu4"},{"binary_name":"nbdkit-plugin-python","binary_version":"1.24.1-2ubuntu4"},{"binary_version":"1.24.1-2ubuntu4","binary_name":"nbdkit-plugin-ruby"},{"binary_name":"nbdkit-plugin-tcl","binary_version":"1.24.1-2ubuntu4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3716.json"}},{"package":{"name":"nbdkit","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/nbdkit?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.34.4-1ubuntu1","1.36.1-1ubuntu1","1.36.2-1ubuntu1","1.36.3-1ubuntu2","1.36.3-1ubuntu3","1.36.3-1ubuntu9","1.36.3-1ubuntu10"],"ecosystem_specific":{"binaries":[{"binary_version":"1.36.3-1ubuntu10","binary_name":"nbdkit"},{"binary_version":"1.36.3-1ubuntu10","binary_name":"nbdkit-plugin-guestfs"},{"binary_version":"1.36.3-1ubuntu10","binary_name":"nbdkit-plugin-libvirt"},{"binary_name":"nbdkit-plugin-lua","binary_version":"1.36.3-1ubuntu10"},{"binary_name":"nbdkit-plugin-perl","binary_version":"1.36.3-1ubuntu10"},{"binary_name":"nbdkit-plugin-python","binary_version":"1.36.3-1ubuntu10"},{"binary_version":"1.36.3-1ubuntu10","binary_name":"nbdkit-plugin-ruby"},{"binary_name":"nbdkit-plugin-tcl","binary_version":"1.36.3-1ubuntu10"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3716.json"}},{"package":{"name":"nbdkit","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/nbdkit?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.42.2-1ubuntu1","1.42.3-1ubuntu1","1.42.4-1ubuntu1","1.42.6-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"nbdkit","binary_version":"1.42.6-1ubuntu1"},{"binary_version":"1.42.6-1ubuntu1","binary_name":"nbdkit-plugin-guestfs"},{"binary_name":"nbdkit-plugin-libvirt","binary_version":"1.42.6-1ubuntu1"},{"binary_name":"nbdkit-plugin-lua","binary_version":"1.42.6-1ubuntu1"},{"binary_name":"nbdkit-plugin-perl","binary_version":"1.42.6-1ubuntu1"},{"binary_name":"nbdkit-plugin-python","binary_version":"1.42.6-1ubuntu1"},{"binary_name":"nbdkit-plugin-tcl","binary_version":"1.42.6-1ubuntu1"},{"binary_name":"nbdkit-plugin-vddk","binary_version":"1.42.6-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3716.json"}},{"package":{"name":"nbdkit","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/nbdkit?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.42.6-1ubuntu1","1.42.9-1ubuntu1","1.42.9-1ubuntu2","1.46.2-1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.46.2-1ubuntu2","binary_name":"nbdkit"},{"binary_version":"1.46.2-1ubuntu2","binary_name":"nbdkit-plugin-guestfs"},{"binary_name":"nbdkit-plugin-libvirt","binary_version":"1.46.2-1ubuntu2"},{"binary_name":"nbdkit-plugin-lua","binary_version":"1.46.2-1ubuntu2"},{"binary_name":"nbdkit-plugin-perl","binary_version":"1.46.2-1ubuntu2"},{"binary_name":"nbdkit-plugin-python","binary_version":"1.46.2-1ubuntu2"},{"binary_version":"1.46.2-1ubuntu2","binary_name":"nbdkit-plugin-tcl"},{"binary_version":"1.46.2-1ubuntu2","binary_name":"nbdkit-plugin-vddk"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3716.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]}