CVE-2026-18358

NameCVE-2026-18358
DescriptionA flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gnome-remote-desktop (PTS)bullseye0.1.9-5undetermined
bookworm43.3-1undetermined
trixie48.1-4undetermined
forky, sid50.2-1undetermined

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gnome-remote-desktopsource(unstable)undetermined

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2462876
does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug

Search for package or bug name: Reporting problems