{"id":"UBUNTU-CVE-2025-32900","details":"In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.","modified":"2026-05-20T16:21:23.440516980Z","published":"2025-12-05T06:16:00Z","upstream":["CVE-2025-32900"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-32900"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-32900"}],"affected":[{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8-0ubuntu5"],"ecosystem_specific":{"binaries":[{"binary_version":"0.8-0ubuntu5","binary_name":"kdeconnect"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-32900.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.3-0ubuntu2","1.2.1-0ubuntu1","1.2.1-0ubuntu2","1.3.0-0ubuntu1","1.3.1-0ubuntu0.1","1.3.3-0ubuntu0.18.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.3-0ubuntu0.18.04.1","binary_name":"kdeconnect"},{"binary_name":"kdeconnect-plasma","binary_version":"1.3.3-0ubuntu0.18.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-32900.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.5-0ubuntu1","1.4-0ubuntu1","1.4-0ubuntu2","1.4-0ubuntu3","1.4-0ubuntu4","1.4-0ubuntu5"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"1.4-0ubuntu5"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-32900.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["21.08.1-0ubuntu1","21.08.1-0ubuntu2","21.08.3-0ubuntu1","21.08.3-1ubuntu1","21.11.80-0ubuntu1","21.11.90-0ubuntu1","21.11.90-0ubuntu2","21.12.0-0ubuntu1","21.12.1-0ubuntu1","21.12.2-0ubuntu1","21.12.3-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"21.12.3-0ubuntu1","binary_name":"kdeconnect"},{"binary_name":"nautilus-kdeconnect","binary_version":"21.12.3-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-32900.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["23.08.1-0ubuntu1","23.08.2-0ubuntu1","23.08.3-0ubuntu1","23.08.4-0ubuntu1","23.08.5-0ubuntu1","23.08.5-0ubuntu4","23.08.5-0ubuntu5"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"23.08.5-0ubuntu5"},{"binary_version":"23.08.5-0ubuntu5","binary_name":"nautilus-kdeconnect"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-32900.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["24.12.3-0ubuntu2","25.04.0-0ubuntu1","25.04.0-0ubuntu2","25.04.1-0ubuntu1","25.04.2-0ubuntu2","25.04.2-1ubuntu1","25.04.3-0ubuntu1","25.07.80-0ubuntu1","25.07.90-0ubuntu1","25.08.0-0ubuntu1","25.08.1-0ubuntu1","25.08.1-0ubuntu2","25.08.1-0ubuntu2.1"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"25.08.1-0ubuntu2.1"},{"binary_name":"kdeconnect-libs","binary_version":"25.08.1-0ubuntu2.1"},{"binary_version":"25.08.1-0ubuntu2.1","binary_name":"nautilus-kdeconnect"},{"binary_name":"qml6-module-org-kde-kdeconnect","binary_version":"25.08.1-0ubuntu2.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-32900.json"}},{"package":{"name":"kdeconnect","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/kdeconnect?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["25.08.1-0ubuntu2","25.08.2-0ubuntu2","25.08.3-0ubuntu1","25.11.80-0ubuntu1","25.11.80-0ubuntu2","25.11.90-0ubuntu1","25.12.0-0ubuntu1","25.12.1-0ubuntu1","25.12.1-0ubuntu2","25.12.2-0ubuntu1","25.12.2-0ubuntu3","25.12.3-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"kdeconnect","binary_version":"25.12.3-0ubuntu1"},{"binary_version":"25.12.3-0ubuntu1","binary_name":"kdeconnect-libs"},{"binary_version":"25.12.3-0ubuntu1","binary_name":"nautilus-kdeconnect"},{"binary_version":"25.12.3-0ubuntu1","binary_name":"qml6-module-org-kde-kdeconnect"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-32900.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}