๐Ÿ” CVE Alert

CVE-2025-5024

HIGH 7.4

Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.

CWE CWE-400
Vendor red hat
Product red hat enterprise linux 10
Published May 22, 2025
Last Updated Nov 20, 2025
Stay Ahead of the Next One

Get instant alerts for red hat red hat enterprise linux 10

Be the first to know when new high vulnerabilities affecting red hat red hat enterprise linux 10 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 8.2 Advanced Update Support
All versions affected
Red Hat / Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
All versions affected
Red Hat / Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
All versions affected
Red Hat / Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
All versions affected
Red Hat / Red Hat Enterprise Linux 8.6 Telecommunications Update Service
All versions affected
Red Hat / Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
All versions affected
Red Hat / Red Hat Enterprise Linux 8.8 Telecommunications Update Service
All versions affected
Red Hat / Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
All versions affected
Red Hat / Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
All versions affected
Red Hat / Red Hat Enterprise Linux 9.4 Extended Update Support
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2025:10631 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:10635 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:10742 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:11403 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:11404 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:11405 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:11406 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:11407 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:11408 access.redhat.com: https://access.redhat.com/errata/RHSA-2025:11418 access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-5024 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2367717 gitlab.gnome.org: https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/merge_requests/321