CVE Vulnerabilities

CVE-2023-5563

Improper Check or Handling of Exceptional Conditions

Published: Oct 13, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception.

Weakness

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product.

Affected Software

Name Vendor Start Version End Version
Zephyr Zephyrproject * 3.4.0 (including)

References