CVE-2025-4478

Public on 2025-05-16
Modified on 2025-05-19
Description
gnome-remote-desktop: Unauthenticated RDP Packet Causes Segfault in gnome-remote-desktop Leading to Denial of Service. The vulnerability stems from improper handling of malformed RDP packets in gnome-remote-desktop when remote access is enabled. An unauthenticated attacker can trigger a segmentation fault, leaving the service in a defunct state and causing a denial-of-service condition until a manual reboot is performed.
Severity
Important severity
Important
CVSS v3 Base Score
7.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 2023 gnome-remote-desktop Pending Fix

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
NVD CVSSv3 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H