Remote Desktop Protocol Vulnerability in Red Hat Enterprise Linux
CVE-2026-18358
7.5HIGH
Key Information:
- Vendor
Gnome
- Status
- Vendor
- CVE Published:
- 31 July 2026
What is CVE-2026-18358?
A vulnerability exists in the gnome-remote-desktop component of Red Hat Enterprise Linux, where the connection handler fails to throttle incoming connections when RDP is enabled. This oversight allows unauthenticated attackers to initiate multiple pre-authentication connections, potentially leading to resource exhaustion. As a result, legitimate users may encounter difficulties in establishing RDP sessions, as the system becomes overwhelmed by the accumulation of accepted sockets and pending routing operations.
Affected Version(s)
Red Hat Enterprise Linux 10 0:49.3-4.el10_2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.