CVE-2025-32899

Description

A flaw was found in KDE Connect. This vulnerability allows two paired devices to unpair via an invalid discovery packet sent over broadcast User Datagram Protocol (UDP).

Statement

This vulnerability is rated Moderate for Red Hat as it allows an unauthenticated attacker on the same local network segment to unpair KDE Connect devices. This flaw primarily impacts the availability of the KDE Connect service by disrupting established device pairings.

Mitigation

To mitigate this issue, restrict network access to systems running KDE Connect. Configure firewall rules to limit UDP traffic on the KDE Connect discovery port (default 1716) to only allow communication from trusted hosts or subnets. This may impact the ability of KDE Connect to discover and pair with new devices if not configured correctly.

Understanding the Weakness (CWE)

Other

Technical Impact: Unexpected State

One or more of the components/sub-systems could assume that the state is different than it actually is.

Frequently Asked Questions

Want to get errata notifications? Sign up here.