← All Advisories

RHEL gnome-remote-desktop RDP listener bypasses connection throttling allowing pre-authentication connection exhaustion

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-18358

Key Details

CVECVE-2026-18358
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-08-13
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Classified asCWE-400 (Uncontrolled Resource Consumption)

What to Know

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-18358
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-18358