CVE-2025-5024: Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus
A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.
Other sources
Once gnome-remote-desktop is listening for RDP connections, an unauthenticated attacker can exhaust system resources and crash the process repeatedly. In fact, there is some sort of resource leak that after many attacks, will result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5024?
CVE-2025-5024 has been classified as a high severity vulnerability due to its potential for causing resource exhaustion and process crashes.
How do I fix CVE-2025-5024?
To mitigate CVE-2025-5024, ensure that gnome-remote-desktop is updated to the latest version that addresses this vulnerability.
What systems are affected by CVE-2025-5024?
CVE-2025-5024 specifically affects systems running GNOME Remote Desktop.
What impact does CVE-2025-5024 have on system performance?
CVE-2025-5024 can lead to significant performance degradation as it allows an attacker to exhaust system resources and crash the gnome-remote-desktop service.
Is CVE-2025-5024 an authenticated vulnerability?
CVE-2025-5024 is an unauthenticated vulnerability, allowing attackers to exploit it without any prior authentication.