Bug#1148894: gnome-remote-desktop: CVE-2026-96541

Salvatore Bonaccorso carnil at debian.org
Thu Sep 24 19:34:01 BST 2026


Source: gnome-remote-desktop
Version: 50.2-1
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/356
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>

Hi,

The following vulnerability was published for gnome-remote-desktop.

CVE-2026-96541[0]:
| A denial-of-service flaw was found in gnome-remote-desktop. An
| unauthenticated remote attacker can open RDP connections without
| completing the handshake and retain the connection-throttling slots
| indefinitely because no pre-authentication handshake deadline is
| enforced. By exhausting the global connection limit, an attacker can
| prevent new RDP clients from connecting until a holding socket is
| closed.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-96541
    https://www.cve.org/CVERecord?id=CVE-2026-96541
[1] https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/356
[2] https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/commit/959cd39ae528a6751d94b0dcff173a470a5bc7ef

Regards,
Salvatore



More information about the pkg-gnome-maintainers mailing list