CVE-2026-18358
Received Received - Intake

gnome-remote-desktop RDP Connection Throttler Bypass

Vulnerability report for CVE-2026-18358, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: Red Hat, Inc.

Description

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat gnome_remote_desktop *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a flaw in gnome-remote-desktop for Red Hat Enterprise Linux when running in system mode with RDP enabled. It allows an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This bypasses the connection throttler and exhausts system resources, preventing legitimate users from establishing RDP sessions.

Detection Guidance

Check if gnome-remote-desktop is running in system mode with RDP enabled. Look for excessive unauthenticated connections to the RDP port (default 3389). Monitor system resource usage for socket exhaustion or pending operations.

Impact Analysis

An attacker could exploit this to crash the RDP service or cause a denial of service, preventing you from accessing your system remotely via RDP. It does not allow data access or modification but disrupts normal operations.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt remote desktop services. Resource exhaustion may lead to unauthorized access prevention, potentially violating availability requirements in these regulations.

Mitigation Strategies

Disable RDP in gnome-remote-desktop when running in system mode with RDP enabled. Monitor system resources for socket exhaustion or pending operations. Apply patches from Red Hat if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18358. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart