CVE-2026-18358

EUVD-2026-51528
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 42.76%
Debian logo
Debian Releases
Debian Product
Codename
gnome-remote-desktop
bookworm
undetermined
forky
undetermined
sid
undetermined
trixie
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnome-remote-desktop
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
gnome-remote-desktop
Amazon Linux 2023
0:47.3-1.amzn2023.0.3
fixed
gnome-remote-desktop-debuginfo
Amazon Linux 2023
0:47.3-1.amzn2023.0.3
fixed
gnome-remote-desktop-debugsource
Amazon Linux 2023
0:47.3-1.amzn2023.0.3
fixed