CVE-2026-18358

GNOME · gnome-remote-desktop

A vulnerability in gnome-remote-desktop allows for uncontrolled resource consumption, potentially leading to a denial of service condition.

Executive summary

A resource consumption vulnerability in gnome-remote-desktop on Red Hat Enterprise Linux may allow unauthenticated remote attackers to cause a denial of service.

Vulnerability

This is an uncontrolled resource consumption vulnerability (CWE-400) that can be triggered by an unauthenticated attacker over the network. The flaw allows an attacker to exhaust system resources, resulting in a denial of service.

Business impact

A successful exploit could cause the gnome-remote-desktop service to become unavailable, disrupting remote management capabilities and workflow productivity. Given the CVSS score of 7.5, the potential for a denial of service against critical infrastructure components represents a high risk to system availability.

Remediation

Immediate Action: Consult the Red Hat security advisory to identify the specific updated packages and apply them to affected RHEL 8, 9, and 10 systems.

Proactive Monitoring: Monitor system resource usage, specifically memory and CPU, for the gnome-remote-desktop process to detect potential exhaustion attempts.

Compensating Controls: Restrict network access to remote desktop ports to trusted IP addresses only, reducing the ability of unauthenticated attackers to reach the service.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk of denial of service is significant for systems relying on remote desktop functionality. Administrators should verify their versions against the Red Hat advisory and apply the necessary patches immediately to restore system stability and prevent service disruption.