CVE-2025-1673: Out of bounds read when calling crc16_ansi and strlen in dns_validate_msg
Published Feb 25, 2025
·Updated
A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect computation.
Affected Software
1 affected component
zephyrproject zephyr<=4.0
Event History
Feb 25, 2025
CVE Published
via MITRE·07:12 AM
Data Sourced
via MITRE·07:12 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-1673?
CVE-2025-1673 is classified as a denial of service vulnerability due to its ability to cause a crash.
2
How do I fix CVE-2025-1673?
To mitigate CVE-2025-1673, upgrade to a version of the Zephyr Project Manager beyond 4.0.
3
What causes the vulnerability in CVE-2025-1673?
CVE-2025-1673 is caused by a malicious or malformed DNS packet without a payload leading to an out-of-bounds read.
4
Which versions of Zephyr Project Manager are affected by CVE-2025-1673?
CVE-2025-1673 affects all versions of Zephyr Project Manager up to and including version 4.0.
5
What type of attack can exploit CVE-2025-1673?
CVE-2025-1673 can be exploited through denial of service attacks that result in application crashes.