VDB

CVE-2026-18358

CVE-2026-18358 PUBLISHED CVSS 7.5 HIGH

Reported by redhat · Published July 31, 2026

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
GNOMEgnome-remote-desktop
Red HatRed Hat Enterprise Linux 100:49.3-4.el10_2
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 100:49.3-4.el10_2
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 8
GNOMEgnome-remote-desktop

Timeline

  • Jul 31, 2026 CVE Published
  • Aug 1, 2026 Coalition ESS Score
  • Aug 3, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 13, 2026 Distribution Patch
  • Aug 13, 2026 Security Advisory
  • Aug 13, 2026 CVE Updated
  • Aug 24, 2026 EPSS Score
  • Aug 24, 2026 Distribution Patch
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›