Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23392.
History

Wed, 26 Mar 2025 21:30:00 +0000

Type Values Removed Values Added
Description Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23392.
Title Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability
Weaknesses CWE-835
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2025-03-26T21:16:33.186Z

Updated: 2025-03-26T21:16:33.186Z

Reserved: 2025-03-26T21:16:17.046Z

Link: CVE-2025-2838

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-03-26T22:15:15.803

Modified: 2025-03-26T22:15:15.803

Link: CVE-2025-2838

cve-icon Redhat

No data.