CVE-2026-96541: Uncontrolled Resource Consumption in Red Hat Red Hat Enterprise Linux 10
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed.
AI Analysis
Technical Summary
This vulnerability in gnome-remote-desktop allows an unauthenticated remote attacker to open RDP connections without completing the handshake, thereby retaining connection-throttling slots indefinitely due to the lack of a pre-authentication handshake deadline. By exhausting the global connection limit, the attacker can prevent new RDP clients from connecting until the held sockets are closed. Exploitation requires connections from at least two distinct source IP addresses to fully utilize per-source and global connection limits. Authenticated RDP sessions remain unaffected. The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) and has a CVSS v3.1 base score of 7.5 (high severity) with network attack vector, low complexity, no privileges or user interaction required, and an availability impact.
Potential Impact
An attacker can cause a denial-of-service condition by exhausting the global connection limit for RDP connections in gnome-remote-desktop, preventing new clients from connecting. This affects availability but does not impact confidentiality or integrity. Existing authenticated sessions continue to function normally.
Mitigation Recommendations
Red Hat advises disabling the RDP listener when it is not required or restricting access to the RDP port to trusted networks or hosts at the network boundary. There is currently no known application-level mitigation that allows unrestricted RDP access while preventing this issue. Users should follow the vendor advisory for updates on fixes or additional mitigations.
CVE-2026-96541: Uncontrolled Resource Consumption in Red Hat Red Hat Enterprise Linux 10
Description
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed.
CVSS v3.1
Score 7.5high
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in gnome-remote-desktop allows an unauthenticated remote attacker to open RDP connections without completing the handshake, thereby retaining connection-throttling slots indefinitely due to the lack of a pre-authentication handshake deadline. By exhausting the global connection limit, the attacker can prevent new RDP clients from connecting until the held sockets are closed. Exploitation requires connections from at least two distinct source IP addresses to fully utilize per-source and global connection limits. Authenticated RDP sessions remain unaffected. The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) and has a CVSS v3.1 base score of 7.5 (high severity) with network attack vector, low complexity, no privileges or user interaction required, and an availability impact.
Potential Impact
An attacker can cause a denial-of-service condition by exhausting the global connection limit for RDP connections in gnome-remote-desktop, preventing new clients from connecting. This affects availability but does not impact confidentiality or integrity. Existing authenticated sessions continue to function normally.
Mitigation Recommendations
Red Hat advises disabling the RDP listener when it is not required or restricting access to the RDP port to trusted networks or hosts at the network boundary. There is currently no known application-level mitigation that allows unrestricted RDP access while preventing this issue. Users should follow the vendor advisory for updates on fixes or additional mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-23T12:16:46.357Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-96541","vendor":"Red Hat"}]
Threat ID: 6ab41847f7a7c54106263802
Added to database: 09/23/2026, 18:19:51 UTC
Last enriched: 09/23/2026, 18:32:41 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.