7.5

CVE-2026-18358

Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGNOME
≫
Produkt gnome-remote-desktop
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 10
Default Statusaffected
Version 0:49.3-4.el10_2
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 8
Default Statusunaffected
HerstellerRed Hat
≫
Produkt Red Hat Enterprise Linux 9
Default Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.418
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://access.redhat.com/security/cve/CVE-2026-18358
https://bugzilla.redhat.com/show_bug.cgi?id=2462876
https://access.redhat.com/errata/RHSA-2026:54512