Security Advisory

CVE-2023-5563

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-10-12 23:11:18
Last updated 2024-09-17 17:08:43
Assigner zephyr
State PUBLISHED

Description

The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception.