A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade gnome-remote-desktop | Jul 14, 2025 | May 22, 2025 |
| Amazon_linux_2023 | — | Upgrade gnome-remote-desktopUpgrade gnome-remote-desktop-debuginfoUpgrade gnome-remote-desktop-debugsource | Sep 9, 2025 | May 21, 2025 |
| Debian | — | No solution exists | May 28, 2025 | May 22, 2025 |
| Oracle_linux | — | Upgrade gnome-remote-desktop | Jul 10, 2025 | May 21, 2025 |
| Redhat_linux | — | Upgrade gnome-remote-desktop-debugsourceUpgrade gnome-remote-desktop-debuginfoUpgrade gnome-remote-desktop | Jul 9, 2025 | May 22, 2025 |
| Rocky_linux | — | Upgrade gnome-remote-desktopUpgrade gnome-remote-desktop-debugsourceUpgrade gnome-remote-desktop-debuginfo | Feb 5, 2026 | Jul 29, 2025 |
| Ubuntu | — | No solution exists | Aug 4, 2025 | May 22, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub