2.3low
SecMateSECMATE-2025-0030
VendorSiliconLabs
ProductGecko SDK
VectorCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Timeline
Reported
Nov 24, 2025
Acknowledged
Nov 24, 2025
Published
Feb 19, 2026
Summary
An integer underflow vulnerability is present in Silicon Labs' implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Triggering the underflow can lead to a hard fault, causing a temporary denial of service.