{"id":"UBUNTU-CVE-2025-5024","details":"A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files even after it is restarted via systemd.","modified":"2026-08-20T23:18:09.598297167Z","published":"2025-05-22T15:16:00Z","upstream":["CVE-2025-5024"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-5024"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-5024"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-5024"}],"affected":[{"package":{"name":"gnome-remote-desktop","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/gnome-remote-desktop?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.1.7-1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-remote-desktop","binary_version":"0.1.7-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-5024.json"}},{"package":{"name":"gnome-remote-desktop","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/gnome-remote-desktop?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["40.2-1","41.0-1","41.1-3","41.2-1","42~beta-1","42~rc-1","42.0-1","42.0-2","42.0-4ubuntu1","42.1.1-0ubuntu1","42.2-0ubuntu1","42.3-0ubuntu1","42.4-0ubuntu1","42.7-0ubuntu1","42.9-0ubuntu0.22.04.1","42.9-0ubuntu0.22.04.2"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-remote-desktop","binary_version":"42.9-0ubuntu0.22.04.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-5024.json"}},{"package":{"name":"gnome-remote-desktop","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/gnome-remote-desktop?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["45.0-1","45.1-1","45.1-1build1","46~rc-0ubuntu2","46.0-2","46.1-1","46.2-1~ubuntu24.04.2","46.3-0ubuntu1","46.3-0ubuntu1.1","46.3-0ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_version":"46.3-0ubuntu1.2","binary_name":"gnome-remote-desktop"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-5024.json"}},{"package":{"name":"gnome-remote-desktop","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/gnome-remote-desktop?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["48.0-1","48.1-2","49~alpha-0ubuntu1","49~rc-0ubuntu1","49.0-0ubuntu1","49.0-0ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-remote-desktop","binary_version":"49.0-0ubuntu1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-5024.json"}},{"package":{"name":"gnome-remote-desktop","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/gnome-remote-desktop?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["49.0-0ubuntu1","49.1-1","49.1-2","49.2-1","49.2-2","49.2-2ubuntu1","50~beta-1","50~rc-0ubuntu1","50.0-0ubuntu1","50.0-0ubuntu2","50.2-0ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-remote-desktop","binary_version":"50.2-0ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-5024.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}