CVE-2021-3716
NixOS vulnerability analysis and mitigation

Overview

A security vulnerability (CVE-2021-3716) was discovered in nbdkit, affecting versions 1.12 through 1.26.4. The flaw was related to improper caching of plaintext state across the STARTTLS encryption boundary. This vulnerability was discovered in August 2021 and was fixed in nbdkit versions 1.24.6, 1.26.5, and 1.27.6 (Red Hat Bugzilla, NVD).

Technical details

The vulnerability stems from nbdkit improperly caching the result of NBD_OPT_STRUCTURED_REPLY from a plaintext Man-in-the-Middle (MitM) attacker prior to acting on NBD_OPT_STARTTLS. The CVSS v3.1 base score is 3.1 (LOW) with vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L. The bug was introduced in nbdkit v1.11.8 (March 2019) with the first implementation of NBD Structured Replies (Openwall, NVD).

Impact

The primary impact of this vulnerability is on system availability. When exploited, it could lead to the client terminating the NBD session. The vulnerability specifically affects older clients that understand TLS but not structured replies, such as qemu versions 2.6 through 2.10, and all versions of nbd-client from 3.15 to present (Openwall).

Exploitability

The vulnerability is exploitable when nbdkit is used in opportunistic mode (--tls=on). A MitM attacker could inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially causing a denial-of-service attack that doesn't trigger until the client performs its first encrypted NBD_CMD_READ (GitLab Commit).

Mitigation and workarounds

The vulnerability can be mitigated by using nbdkit in forced TLS mode (--tls=require) instead of opportunistic mode. Additionally, all impacted nbdkit versions give successful replies to repeated NBD_OPT_STRUCTURED_REPLY requests, so clients that request structured replies after STARTTLS will not see any change in behavior despite the MitM injection (Openwall).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management