{"id":"UBUNTU-CVE-2026-96541","details":"A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed.","modified":"2026-09-25T06:37:24.008680152Z","published":"2026-09-24T00:00:00Z","upstream":["CVE-2026-96541"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-96541"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-96541"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/356"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-96541"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539385"}],"affected":[{"package":{"name":"gnome-remote-desktop","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/gnome-remote-desktop?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.1.7-1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-remote-desktop","binary_version":"0.1.7-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96541.json"}},{"package":{"name":"gnome-remote-desktop","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/gnome-remote-desktop?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["40.2-1","41.0-1","41.1-3","41.2-1","42~beta-1","42~rc-1","42.0-1","42.0-2","42.0-4ubuntu1","42.1.1-0ubuntu1","42.2-0ubuntu1","42.3-0ubuntu1","42.4-0ubuntu1","42.7-0ubuntu1","42.9-0ubuntu0.22.04.1","42.9-0ubuntu0.22.04.2"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-remote-desktop","binary_version":"42.9-0ubuntu0.22.04.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96541.json"}},{"package":{"name":"gnome-remote-desktop","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/gnome-remote-desktop?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["45.0-1","45.1-1","45.1-1build1","46~rc-0ubuntu2","46.0-2","46.1-1","46.2-1~ubuntu24.04.2","46.3-0ubuntu1","46.3-0ubuntu1.1","46.3-0ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_version":"46.3-0ubuntu1.2","binary_name":"gnome-remote-desktop"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96541.json"}},{"package":{"name":"gnome-remote-desktop","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/gnome-remote-desktop?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["49.0-0ubuntu1","49.1-1","49.1-2","49.2-1","49.2-2","49.2-2ubuntu1","50~beta-1","50~rc-0ubuntu1","50.0-0ubuntu1","50.0-0ubuntu2","50.2-0ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-remote-desktop","binary_version":"50.2-0ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-96541.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}