CVE-2026-96541: 
Linux Debian 脆弱性の分析と軽減

概要

CVE-2026-96541 is a denial-of-service vulnerability in gnome-remote-desktop caused by the absence of a pre-authentication handshake deadline for RDP connections. An unauthenticated remote attacker can open RDP connections without completing the handshake, retaining connection-throttling slots indefinitely and exhausting the global connection limit, thereby preventing legitimate RDP clients from connecting. The vulnerability affects gnome-remote-desktop releases from version 50.beta onward, including 50.0 through 50.2 and reviewed 51 prereleases and the main branch (Red Hat CVE, Red Hat Bugzilla). It was disclosed on September 23, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).

技術的な詳細

The root cause is CWE-400 (Uncontrolled Resource Consumption): the GrdThrottler component charges accepted TCP connections against per-source and global connection limits before authentication, but imposes no absolute deadline requiring the peer to complete the RDP handshake (Red Hat Bugzilla). An attacker can therefore hold admitted sockets open indefinitely, retaining all available connection slots. With default limits, an attacker operating from just two source IP addresses can hold five connections each (ten total), exhausting the global slot pool and blocking all new RDP handshakes until a holding connection is closed (Red Hat CVE). This is described as an incomplete fix for CVE-2025-5024, introduced with the GrdThrottler commit (959cd39a). The attack requires no privileges or user interaction and is fully network-exploitable (GitHub Advisory).

影響

Successful exploitation results in a complete denial of service for the gnome-remote-desktop RDP listener: new RDP clients are unable to establish connections until the attacker releases their held sockets (Red Hat CVE). Existing authenticated RDP sessions are not terminated and remain unaffected. There is no confidentiality, integrity, or code-execution impact — the vulnerability is limited to availability (Red Hat Bugzilla).

エクスプロイト可能性

The vulnerability is automatable and requires no authentication, privileges, or user interaction, making it straightforward to exploit at scale (Red Hat CVE). A proof-of-concept reproducer was included in the upstream GNOME issue report at the time of filing (Red Hat Bugzilla). No confirmed in-the-wild exploitation has been observed, and the EPSS score is 0.0 as of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog. No specific threat actor attribution is available.

エクスプロイテーションのステップ

  1. Reconnaissance: Identify hosts running gnome-remote-desktop with the RDP listener enabled (versions 50.beta through 50.2 or 51 prereleases) by scanning for open RDP ports (default TCP 3389) using tools such as Nmap or Masscan.
  2. Establish incomplete RDP connections: From at least two distinct source IP addresses, open TCP connections to the target's RDP port without completing the RDP handshake (e.g., send the initial TCP SYN but do not proceed with the RDP protocol negotiation, or initiate the connection and then stall).
  3. Exhaust connection slots: With default limits, hold five connections from each of two source IPs (ten total) to fill the global connection pool. The GrdThrottler will count these unauthenticated sockets against the global limit indefinitely since no handshake deadline is enforced.
  4. Deny service: Once all ten global slots are occupied, any new legitimate RDP client attempting to connect will be refused until the attacker releases one of the holding connections (Red Hat Bugzilla, Red Hat CVE).

妥協の兆候

  • Network: Unusually high number of half-open or stalled TCP connections to the RDP port (default 3389) from a small set of source IP addresses; connections that persist without completing the RDP handshake for extended periods.
  • Logs: gnome-remote-desktop logs showing repeated connection slot allocation from the same source IPs without corresponding authentication or session establishment events; log entries indicating the global connection limit has been reached.
  • Process/System: ss or netstat output showing many TCP connections in ESTABLISHED state to the RDP port with no associated authenticated session activity; connection count at or near the configured global limit with no legitimate user sessions.

軽減策と回避策

The primary recommended mitigations are to disable the RDP listener when it is not required, or to restrict access to the RDP port to trusted networks or hosts at the network boundary (e.g., via firewall rules) (Red Hat CVE). No application-level mitigation that preserves unrestricted RDP access is known. A patch is available via the GitHub Advisory (GHSA-gv4j-r8qw-8qpc); users should apply the upstream fix that enforces a pre-authentication handshake deadline (GitHub Advisory). Specific fixed version numbers were not published at the time of disclosure.

コミュニティの反応

Red Hat classified this as a Moderate-impact vulnerability and noted that exploitation requires connecting from at least two distinct source IP addresses to fully exhaust the default per-source and global connection limits (Red Hat CVE). The upstream GNOME project acknowledged the report, with Bynario Atlas credited as the original reporter (Red Hat CVE). No significant broader media coverage or notable researcher commentary beyond the official advisories has been observed.

関連情報

Linuxディストリビューションの修正状況

主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。

Debian

修正済

bookworm

gnome-remote-desktop

修正済

sid

gnome-remote-desktop

影響

trixie

gnome-remote-desktop

修正済

Ubuntu

不明

devel

gnome-remote-desktop

不明

focal (esm-apps)

gnome-remote-desktop

不明

jammy

gnome-remote-desktop

不明

noble

gnome-remote-desktop

不明

resolute

gnome-remote-desktop

不明

RHEL / CentOS

影響

RHEL 8

gnome-remote-desktop.src

影響

RHEL 9

gnome-remote-desktop.src

影響

RHEL 10

gnome-remote-desktop.src

影響

ソース: このレポートは AI を使用して生成されました

関連 Linux Debian 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-97152HIGH8.6
  • Linux Debian logoLinux Debian
  • nanomsg
いいえいいえSep 24, 2026
CVE-2026-96889HIGH7.8
  • Linux Debian logoLinux Debian
  • librsvg2-tools
いいえいいえSep 23, 2026
CVE-2026-59980MEDIUM6.3
  • Linux Debian logoLinux Debian
  • python-hpack
いいえいいえSep 23, 2026
CVE-2026-97149MEDIUM5.3
  • Linux Debian logoLinux Debian
  • swift
いいえいいえSep 24, 2026
CVE-2026-96546LOW2.5
  • Linux Debian logoLinux Debian
  • gimp-help-browser
いいえいいえSep 23, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者