CVE-2023-5563: High severity zephyr project manager vulnerability
Published Oct 12, 2023
·Updated
The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIGCANAUTOBUSOFFRECOVERY=y. This results in calling ksleep() in IRQ context, causing a fatal exception.
Affected Software
1 affected component
zephyrproject zephyr<=3.4.0
Event History
Oct 12, 2023
CVE Published
via MITRE·11:11 PM
Data Sourced
via MITRE·11:11 PM
DescriptionSeverityWeakness
Oct 13, 2023
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-5563?
CVE-2023-5563 is a vulnerability in the SJA1000 CAN controller driver backend that causes a fatal exception when attempting to recover from a bus-off event in IRQ context.
2
How does the SJA1000 CAN controller driver backend recover from a bus-off event?
The SJA1000 CAN controller driver backend attempts to recover from a bus-off event automatically when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y.
3
What is the severity of CVE-2023-5563?
CVE-2023-5563 has a severity rating of 7.1 (high).
4
Which software versions are affected by CVE-2023-5563?
CVE-2023-5563 affects Zephyrproject Zephyr versions up to and including 3.4.0.
5
How can I fix CVE-2023-5563?
To fix CVE-2023-5563, update Zephyrproject Zephyr to a version later than 3.4.0.