DEBIAN-CVE-2026-96541

Source
https://security-tracker.debian.org/tracker/CVE-2026-96541
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-96541.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-96541
Upstream
  • CVE-2026-96541
Published
2026-09-23T19:19:54Z
Modified
2026-09-25T08:47:32Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed.

References

Affected packages

Debian:14 / gnome-remote-desktop

Package

Name
gnome-remote-desktop
Purl
pkg:deb/debian/gnome-remote-desktop?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

48.*
48.1-4
48.2-1
49.*
49.0-1
49.1-1
49.1-2
49.2-1
49.2-2
49.2-3
49.2-4
Other
50~beta-1
50.*
50.1-1
50.1-2
50.1-3
50.1-5
50.2-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-96541.json"