Linbit develops specialized cluster and storage replication software, principally the DRBD distributed block device and the Csync2 file synchronization tool, which are embedded in high-availability and data-protection infrastructure. The observed vulnerability surface reflects the complexity of state management and privilege handling inherent to kernel-level storage and filesystem coordination, with recurrent patterns in permission assignment, return-value validation, and incomplete error handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linbit over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15522CRITICAL An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL. | Mar 20, 2020 | 9.8 | 31 | NO | NO |
CVE-2010-0747HIGH drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725. | Oct 30, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-15523MEDIUM An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglec | Dec 30, 2020 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linbit.
Media articles that mention a CVE ID that affects a product developed by Linbit — matched by CVE ID, not by vendor name.