{"id":"DEBIAN-CVE-2026-96541","details":"A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed.","modified":"2026-09-25T08:47:32.162767620Z","published":"2026-09-23T19:19:54.080Z","upstream":["CVE-2026-96541"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-96541"}],"affected":[{"package":{"name":"gnome-remote-desktop","ecosystem":"Debian:14","purl":"pkg:deb/debian/gnome-remote-desktop?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["48.1-4","48.2-1","49.0-1","49.1-1","49.1-2","49.2-1","49.2-2","49.2-3","49.2-4","50.1-1","50.1-2","50.1-3","50.1-5","50.2-1","50~beta-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-96541.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}