GNOME-RD: Unauth RDP Resource Exhaustion Crash in gnome-remote-desktop
CVE-2025-5024 Published on May 22, 2025
Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus
A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.
Vulnerability Analysis
CVE-2025-5024 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is a Resource Exhaustion Vulnerability?
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVE-2025-5024 has been classified to as a Resource Exhaustion vulnerability or weakness.
Products Associated with CVE-2025-5024
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Enterprise Linux 10:- Version 0:47.3-2.el10_0 and below * is unaffected.
- Version 0:0.1.8-4.el8_10 and below * is unaffected.
- Version 0:0.1.6-9.el8_2.1 and below * is unaffected.
- Version 0:0.1.8-4.el8_4 and below * is unaffected.
- Version 0:0.1.8-4.el8_4 and below * is unaffected.
- Version 0:0.1.8-4.el8_6 and below * is unaffected.
- Version 0:0.1.8-4.el8_6 and below * is unaffected.
- Version 0:0.1.8-4.el8_6 and below * is unaffected.
- Version 0:0.1.8-4.el8_8 and below * is unaffected.
- Version 0:0.1.8-4.el8_8 and below * is unaffected.
- Version 0:40.0-11.el9_6 and below * is unaffected.
- Version 0:40.0-10.el9_0 and below * is unaffected.
- Version 0:40.0-10.el9_2 and below * is unaffected.
- Version 0:40.0-11.el9_4 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.