The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23392.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8257 | Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23392. |
Fri, 08 Aug 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Silabs
Silabs gecko Os |
|
| CPEs | cpe:2.3:o:silabs:gecko_os:1.0.46:*:*:*:*:*:*:* | |
| Vendors & Products |
Silabs
Silabs gecko Os |
Thu, 27 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Mar 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Silicon Labs Gecko OS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of DNS responses. The issue results from a logic error that can lead to an infinite loop. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23392. | |
| Title | Silicon Labs Gecko OS DNS Response Processing Infinite Loop Denial-of-Service Vulnerability | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2025-03-27T14:52:53.920Z
Reserved: 2025-03-26T21:16:17.046Z
Link: CVE-2025-2838
Updated: 2025-03-27T14:52:29.644Z
Status : Analyzed
Published: 2025-03-26T22:15:15.803
Modified: 2025-08-08T01:00:12.240
Link: CVE-2025-2838
No data.
OpenCVE Enrichment
No data.
EUVD