DEBIAN-CVE-2026-18358

Source
https://security-tracker.debian.org/tracker/CVE-2026-18358
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-18358.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-18358
Upstream
  • CVE-2026-18358
Published
2026-07-31T13:17:19Z
Modified
2026-09-14T17:02:50Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.

References

Affected packages

Debian:12 / gnome-remote-desktop

Package

Name
gnome-remote-desktop
Purl
pkg:deb/debian/gnome-remote-desktop?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

43.*
43.3-1
43.4-1
43.4-2
Other
44~rc-1
45~beta-1
45~rc-1
47~beta-1
47~rc-1
48~alpha-1
48~alpha-2
50~beta-1
44.*
44.0-1
44.1-1
44.2-1
44.2-2
44.2-3
44.2-4
44.2-5
44.2-6
44.2-7
44.2-8
45.*
45.0-1
45.1-1
45.1-2
45.1-3
46.*
46.0-1
46.0-2
46.1-1
46.1-2
46.1-3
46.2-1
46.3-1
46.3-2
46.3-3
46.3-4
46.4-1
47.*
47.0-1
47.0-3
47.2-1
47.3-1
48.*
48.0-1
48.1-1
48.1-2
48.1-3
48.1-4
48.2-1
49.*
49.0-1
49.1-1
49.1-2
49.2-1
49.2-2
49.2-3
49.2-4
50.*
50.1-1
50.1-2
50.1-3
50.1-5
50.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-18358.json"

Debian:13 / gnome-remote-desktop

Package

Name
gnome-remote-desktop
Purl
pkg:deb/debian/gnome-remote-desktop?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

48.*
48.1-4
48.2-1
49.*
49.0-1
49.1-1
49.1-2
49.2-1
49.2-2
49.2-3
49.2-4
Other
50~beta-1
50.*
50.1-1
50.1-2
50.1-3
50.1-5
50.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-18358.json"

Debian:14 / gnome-remote-desktop

Package

Name
gnome-remote-desktop
Purl
pkg:deb/debian/gnome-remote-desktop?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

48.*
48.1-4
48.2-1
49.*
49.0-1
49.1-1
49.1-2
49.2-1
49.2-2
49.2-3
49.2-4
Other
50~beta-1
50.*
50.1-1
50.1-2
50.1-3
50.1-5
50.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-18358.json"