CVE-2019-15523: Debian Linux

Medium severity, CVSS 5.3. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as required by the design of the API.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Linbit CSYNC2: up to and including 2.0

Published 2020-12-30. Last modified 2026-06-17.