VDB
CVE-2026-18358
CVE-2026-18358
PUBLISHED
CVSS 7.5 HIGH
Reported by redhat · Published July 31, 2026
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GNOME | gnome-remote-desktop | |
| Red Hat | Red Hat Enterprise Linux 10 | 0:49.3-4.el10_2 |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 10 | 0:49.3-4.el10_2 |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Enterprise Linux 8 | |
| GNOME | gnome-remote-desktop |
Timeline
- Jul 31, 2026 CVE Published
- Aug 1, 2026 Coalition ESS Score
- Aug 3, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 13, 2026 Distribution Patch
- Aug 13, 2026 Security Advisory
- Aug 13, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
- Aug 24, 2026 Distribution Patch
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
References
- RHSA-2026:54512 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2462876 issue-trackingx_refsource_REDHAT