CVE-2025-5024
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
22/05/2025
Last modified:
12/08/2025
Description
A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://access.redhat.com/errata/RHSA-2025:10631
- https://access.redhat.com/errata/RHSA-2025:10635
- https://access.redhat.com/errata/RHSA-2025:10742
- https://access.redhat.com/errata/RHSA-2025:11403
- https://access.redhat.com/errata/RHSA-2025:11404
- https://access.redhat.com/errata/RHSA-2025:11405
- https://access.redhat.com/errata/RHSA-2025:11406
- https://access.redhat.com/errata/RHSA-2025:11407
- https://access.redhat.com/errata/RHSA-2025:11408
- https://access.redhat.com/errata/RHSA-2025:11418
- https://access.redhat.com/security/cve/CVE-2025-5024
- https://bugzilla.redhat.com/show_bug.cgi?id=2367717
- https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/merge_requests/321



