What is CVE-2026-18358?
A vulnerability in gnome-remote-desktop, as shipped with Red Hat Enterprise Linux, allows unauthenticated remote attackers to bypass the connection throttler when the daemon runs in system mode with RDP enabled. This enables opening numerous parallel pre-authentication connections, potentially leading to denial of service. Applying the vendor-provided security update is recommended.
Azərbaycanca: Bu qüsur Red Hat Enterprise Linux-da təqdim edilən gnome-remote-desktop-daemon-un RDP aktiv olduqda sistem rejimində işləyərkən qoşulma məhdudlaşdırıcısını (connection throttler) keçməsinə imkan verir. Bu, autentifikasiya olunmamış uzaq təcavüzkara çoxsaylı paralel pre-autentifikasiya bağlantısı açaraq xidmətə hücum etməyə şərait yaradır. Təsirə məruz qalmamaq üçün Red Hat-ın təqdim etdiyi təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
FAQ2
How can one protect against CVE-2026-18358?
It is recommended to apply the security update provided for Red Hat Enterprise Linux.
Is authentication required to exploit CVE-2026-18358?
No, this vulnerability can be exploited by unauthenticated remote attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.