---
id: CVE-2025-5024
title: A flaw was found in gnome-remote-desktop
summary: >-
  A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens
  for RDP connections, an unauthenticated attacker can exhaust system resources
  and repeatedly crash the process. There may be a resource leak after many
  attacks, …
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H'
cwe:
  - CWE-400
published: '2025-05-22'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-5024'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:10631'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10635'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10742'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11403'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11404'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11405'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11406'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11407'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11408'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11418'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-5024'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2367717'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/merge_requests/321'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.00822
epssPercentile: 0.55798
ingestedAt: '2026-06-29T13:24:34.332Z'
---

## Overview

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
