
CVE-2026-96541
GNOME Remote Desktop
•
severity
published
GNOME Remote Desktop does not enforce a deadline for unauthenticated clients to complete the RDP handshake. A remote attacker can hold admitted connections open indefinitely, exhaust the service's global connection limit, and prevent new RDP clients from connecting until a holding socket is closed.
The service accounts for an accepted TCP connection before RDP, TLS, or NLA authentication completes, then waits without an authentication or idle timeout. Connection throttling limits how many sockets are admitted but does not limit how long an unauthenticated socket can retain its slot. With the default limit of ten global connections and five per source address, an attacker able to use two source identities can occupy every slot without authenticating.
The demonstrated impact is denial of service for new RDP connections; existing authenticated sessions were not shown to terminate. Remediation requires a monotonic deadline from TCP admission through successful authentication, enforced independently of per-source and global connection quotas.
References
Explore our other findings
