The vulnerability stems from improper handling of malformed RDP packets in gnome-remote-desktop when remote access is enabled. An unauthenticated attacker can trigger a segmentation fault, leaving the service in a defunct state and causing a denial-of-service condition until a manual reboot is performed.
Once gnome-remote-desktop is listening for RDP connections, an unauthenticated attacker can exhaust system resources and crash the process repeatedly. In fact, there is some sort of resource leak that after many attacks, will result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.