CVE-2023-5563: Zephyrproject Zephyr
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception.
Affected products
- Zephyrproject Zephyr: up to and including 3.4.0
Published 2023-10-13. Last modified 2026-06-17.