Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
对异常条件检查或处理不恰当
Vulnerability Title
Zephyr 安全漏洞
Vulnerability Description
Zephyr是Zephyr Project开源的一个可扩展的实时操作系统 (RTOS)。 Zephyr 3.4.0及之前版本存在安全漏洞,该漏洞源于当使用 CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y 构建时,SJA1000 CAN 控制器驱动程序后端会自动尝试从总线关闭事件中恢复,导致在 IRQ 上下文中调用 k_sleep(),从而导致致命异常。
CVSS Information
N/A
Vulnerability Type
N/A