
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53043 affects the Linux kernel and involves a vulnerability in the arm64 DTS (Device Tree Source) implementation for the Qualcomm SC7280 PCIe controller. The issue was discovered and reported in May 2025, specifically related to cache coherency handling (NVD).
The vulnerability stems from incorrect cache coherency marking in the PCIe controller configuration. When the controller is not marked as cache coherent, the kernel attempts to ensure coherency during DMA operations, which can potentially lead to data corruption. The fix involves marking the PCIe node as dma-coherent since the devices on the PCIe bus are cache coherent (Debian Tracker).
The primary impact of this vulnerability is potential data corruption during DMA operations on affected systems using the Qualcomm SC7280 PCIe controller. This could affect system stability and data integrity when performing PCIe-related operations (NVD).
The vulnerability has been fixed in various Linux kernel versions. Debian has marked this as fixed in multiple releases: bullseye (5.10.234-1), bookworm (6.1.137-1), and trixie/sid (6.12.27-1). Users should update their kernel to the patched versions to mitigate this issue (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."