CVE-2025-5024

Publication date 22 May 2025

Last updated 5 February 2026


Ubuntu priority

Cvss 3 Severity Score

7.4 · High

Score breakdown

Description

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.

Status

Package Ubuntu Release Status
gnome-remote-desktop 26.04 LTS resolute
Vulnerable
25.10 questing Ignored end of life, was needed
25.04 plucky Ignored end of life, was deferred [2026-01-05]
24.10 oracular Ignored end of life, was needs-triage
24.04 LTS noble
Vulnerable
22.04 LTS jammy
Vulnerable
20.04 LTS focal
Vulnerable

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
gnome-remote-desktop

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.4 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H


Access our resources on patching vulnerabilities