CVE-2025-5024

EUVD-2025-16145
A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Debian logo
Debian Releases
Debian Product
Codename
gnome-remote-desktop
bookworm
no-dsa
bullseye
postponed
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnome-remote-desktop
focal
needed
jammy
needed
noble
needed
oracular
ignored
plucky
ignored
questing
needed
resolute
needed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gnome-remote-desktop
suse enterprise desktop 15 SP7
46.5-150700.3.3.1
fixed
suse enterprise sap 15 SP7
46.5-150700.3.3.1
fixed
suse enterprise server 15 SP7
46.5-150700.3.3.1
fixed
suse enterprise workstation 15 SP7
46.5-150700.3.3.1
fixed
gnome-remote-desktop-lang
suse enterprise desktop 15 SP7
46.5-150700.3.3.1
fixed
suse enterprise sap 15 SP7
46.5-150700.3.3.1
fixed
suse enterprise server 15 SP7
46.5-150700.3.3.1
fixed
suse enterprise workstation 15 SP7
46.5-150700.3.3.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
gnome-remote-desktop
RHEL 9
0:40.0-11.el9_6
fixed