
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-96541 is a denial-of-service vulnerability in gnome-remote-desktop caused by the absence of a pre-authentication handshake deadline for RDP connections. An unauthenticated remote attacker can open RDP connections without completing the handshake, retaining connection-throttling slots indefinitely and exhausting the global connection limit, thereby preventing legitimate RDP clients from connecting. The vulnerability affects gnome-remote-desktop releases from version 50.beta onward, including 50.0 through 50.2 and reviewed 51 prereleases and the main branch (Red Hat CVE, Red Hat Bugzilla). It was disclosed on September 23, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The root cause is CWE-400 (Uncontrolled Resource Consumption): the GrdThrottler component charges accepted TCP connections against per-source and global connection limits before authentication, but imposes no absolute deadline requiring the peer to complete the RDP handshake (Red Hat Bugzilla). An attacker can therefore hold admitted sockets open indefinitely, retaining all available connection slots. With default limits, an attacker operating from just two source IP addresses can hold five connections each (ten total), exhausting the global slot pool and blocking all new RDP handshakes until a holding connection is closed (Red Hat CVE). This is described as an incomplete fix for CVE-2025-5024, introduced with the GrdThrottler commit (959cd39a). The attack requires no privileges or user interaction and is fully network-exploitable (GitHub Advisory).
Successful exploitation results in a complete denial of service for the gnome-remote-desktop RDP listener: new RDP clients are unable to establish connections until the attacker releases their held sockets (Red Hat CVE). Existing authenticated RDP sessions are not terminated and remain unaffected. There is no confidentiality, integrity, or code-execution impact — the vulnerability is limited to availability (Red Hat Bugzilla).
The vulnerability is automatable and requires no authentication, privileges, or user interaction, making it straightforward to exploit at scale (Red Hat CVE). A proof-of-concept reproducer was included in the upstream GNOME issue report at the time of filing (Red Hat Bugzilla). No confirmed in-the-wild exploitation has been observed, and the EPSS score is 0.0 as of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog. No specific threat actor attribution is available.
GrdThrottler will count these unauthenticated sockets against the global limit indefinitely since no handshake deadline is enforced.ss or netstat output showing many TCP connections in ESTABLISHED state to the RDP port with no associated authenticated session activity; connection count at or near the configured global limit with no legitimate user sessions.The primary recommended mitigations are to disable the RDP listener when it is not required, or to restrict access to the RDP port to trusted networks or hosts at the network boundary (e.g., via firewall rules) (Red Hat CVE). No application-level mitigation that preserves unrestricted RDP access is known. A patch is available via the GitHub Advisory (GHSA-gv4j-r8qw-8qpc); users should apply the upstream fix that enforces a pre-authentication handshake deadline (GitHub Advisory). Specific fixed version numbers were not published at the time of disclosure.
Red Hat classified this as a Moderate-impact vulnerability and noted that exploitation requires connecting from at least two distinct source IP addresses to fully exhaust the default per-source and global connection limits (Red Hat CVE). The upstream GNOME project acknowledged the report, with Bynario Atlas credited as the original reporter (Red Hat CVE). No significant broader media coverage or notable researcher commentary beyond the official advisories has been observed.
主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。
devel
gnome-remote-desktop
focal (esm-apps)
gnome-remote-desktop
jammy
gnome-remote-desktop
noble
gnome-remote-desktop
resolute
gnome-remote-desktop
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"