Bug#1148894: gnome-remote-desktop: CVE-2026-96541
Salvatore Bonaccorso
carnil at debian.org
Thu Sep 24 19:34:01 BST 2026
Source: gnome-remote-desktop
Version: 50.2-1
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/356
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerability was published for gnome-remote-desktop.
CVE-2026-96541[0]:
| A denial-of-service flaw was found in gnome-remote-desktop. An
| unauthenticated remote attacker can open RDP connections without
| completing the handshake and retain the connection-throttling slots
| indefinitely because no pre-authentication handshake deadline is
| enforced. By exhausting the global connection limit, an attacker can
| prevent new RDP clients from connecting until a holding socket is
| closed.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-96541
https://www.cve.org/CVERecord?id=CVE-2026-96541
[1] https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/356
[2] https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/commit/959cd39ae528a6751d94b0dcff173a470a5bc7ef
Regards,
Salvatore
More information about the pkg-gnome-maintainers
mailing list