A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-gnome-remote-desktop | Jul 14, 2025 | May 22, 2025 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-gnome-remote-desktopamazon-linux-2023-upgrade-gnome-remote-desktop-debuginfoamazon-linux-2023-upgrade-gnome-remote-desktop-debugsource | Sep 9, 2025 | May 21, 2025 | |
| Debian | no-fix-debian-deb-package | May 28, 2025 | May 22, 2025 | |
| Oracle_linux | — | oracle-linux-upgrade-gnome-remote-desktop | Jul 10, 2025 | May 21, 2025 |
| Redhat_linux | redhat-upgrade-gnome-remote-desktopredhat-upgrade-gnome-remote-desktop-debuginforedhat-upgrade-gnome-remote-desktop-debugsource | Jul 9, 2025 | May 22, 2025 | |
| Rocky_linux | rocky-upgrade-gnome-remote-desktoprocky-upgrade-gnome-remote-desktop-debuginforocky-upgrade-gnome-remote-desktop-debugsource | Feb 5, 2026 | Jul 29, 2025 | |
| Ubuntu | no-fix-ubuntu-package | Aug 4, 2025 | May 22, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub