Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23392.
History

Thu, 27 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 21:30:00 +0000

Type Values Removed Values Added
Description Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23392.
Title Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability
Weaknesses CWE-835
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2025-03-26T21:16:33.186Z

Updated: 2025-03-27T14:52:53.920Z

Reserved: 2025-03-26T21:16:17.046Z

Link: CVE-2025-2838

cve-icon Vulnrichment

Updated: 2025-03-27T14:52:29.644Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-26T22:15:15.803

Modified: 2025-03-27T16:45:27.850

Link: CVE-2025-2838

cve-icon Redhat

No data.