Impact
A denial‑of‑service flaw was discovered in gnome‑remote‑desktop. The component accepts successive Remote Desktop Protocol connections from unauthenticated users and does not enforce a handshake deadline before the connection is fully established. An attacker can therefore open multiple RDP sockets, keep them open indefinitely, and consume the global connection‑throttling slots reserved for legitimate users. This exhaustion of slots prevents new RDP clients from connecting until a socket is closed, effectively disrupting remote desktop service availability. The weakness is identified as CWE‑400, an Uncontrolled Resource Consumption flaw.
Affected Systems
The vulnerability affects Red Hat Enterprise Linux 8, 9, and 10 installed with the gnome‑remote‑desktop service. All three OS releases expose the same uncontrolled retention of RDP sockets when the listener is active.
Risk and Exploitability
The CVSS v3 score of 7.5 indicates high severity, while the EPSS data is unavailable and the issue is not yet cataloged in CISA KEV. An unauthenticated attacker can exploit the flaw simply by initiating RDP connections from any network reachable to the host. The necessary conditions are an open RDP listening socket and no pre‑authentication handshake limit. Because the flaw requires no credentials and the attack surface is exposed on any reachable RDP port, the likelihood of exploitation is high in environments where RDP is left unrestricted.
OpenCVE Enrichment