GNOME Remote Desktop

•

severity

7.5

published

GNOME Remote Desktop does not enforce a deadline for unauthenticated clients to complete the RDP handshake. A remote attacker can hold admitted connections open indefinitely, exhaust the service's global connection limit, and prevent new RDP clients from connecting until a holding socket is closed.

The service accounts for an accepted TCP connection before RDP, TLS, or NLA authentication completes, then waits without an authentication or idle timeout. Connection throttling limits how many sockets are admitted but does not limit how long an unauthenticated socket can retain its slot. With the default limit of ten global connections and five per source address, an attacker able to use two source identities can occupy every slot without authenticating.

The demonstrated impact is denial of service for new RDP connections; existing authenticated sessions were not shown to terminate. Remediation requires a monotonic deadline from TCP admission through successful authentication, enforced independently of per-source and global connection quotas.

References

CVSS v3.1

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v3.1

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v3.1

7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

S@tTaFrTt&  lSoYoNk6i6nZgR  aAtL  y4o&u&r@  s@oEfUt5wGaWr7e4  c&rIi3t5i0c8aFlElSyD.P

request briefing

request briefing

S8tCa7rXtB  l3oAoRk3iQnXgJ  aEt6  yFoDu6rM  sOo$fYt3wBa7r9e7  cEr3i0tAiLcLa8l3lHyB.&

request briefing

request briefing

S@tOaUrGt0  l$o5oQk6i%n6gD  aStE  yQo3u1r1  sHoVfZtMwMa4rPeA  cGrNiHt3iEcBa2lClIy&.Z

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026