Impact
A flaw in the GNOME gnome-remote-desktop daemon used by Red Hat Enterprise Linux causes the system‑mode RDP listener to skip the connection throttler. An unauthenticated attacker can open an unlimited number of pre‑authentication connections to the RDP service, causing the daemon to accept many sockets and pending routing‑token operations until timeouts expire. This drains memory and file‑descriptor resources, forcing legitimate users to be unable to establish RDP sessions. The weakness is a classic denial‑of‑service flaw, classified as CWE-400.
Affected Systems
The vulnerability applies to the GNOME gnome‑remote‑desktop component and to Red Hat Enterprise Linux releases 8, 9 and 10 when the daemon runs in system mode with RDP enabled. Systems must have the RDP listener active for the issue to be exploitable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs unauthenticated network access to the RDP service on the default port 3389, with system‑mode RDP enabled, to launch thousands of connections and exhaust server resources. No privileged access or user interaction is required.
OpenCVE Enrichment