CyberRota Analysis
AI-GeneratedA vulnerability in the gnome-remote-desktop component of Red Hat Enterprise Linux allows unauthenticated remote attackers to bypass the connection throttler when RDP is enabled, leading to resource exhaustion through multiple parallel pre-authentication connections. This can prevent legitimate users from establishing RDP sessions, posing a significant risk to system availability. Organizations using Red Hat Enterprise Linux with RDP enabled should prioritize addressing this issue to safeguard against potential denial-of-service attacks.
Original NVD Description
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.