CVE-2023-53986
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2023-53986 is a vulnerability in the Linux kernel affecting the MIPS BMIPS platform, specifically the BCM6358 SoC. The issue involves the Read-Ahead Cache (RAC) flush mechanism causing kernel panics when booting from Thread Processor 1 (TP1) in the presence of EHCI/OHCI USB hardware. It was published on December 24, 2025, and affects Linux kernel versions prior to the fix. The CVSS category is estimated as Medium, with an EPSS score of 0.000240 (Feedly).

Technical details

The root cause is an improper handling of the RAC (Read-Ahead Cache) flush operation in the MIPS BMIPS BCM6358 platform code when the kernel is booted from TP1 (Thread Processor 1). When EHCI or OHCI USB drivers are loaded, the RAC flush triggers a "Reserved instruction" exception (ExcCode 0a) in kernel code at setup_sigcontext+0x54/0x24c, resulting in a kernel panic. The fix disables the RAC flush for TP1 on BCM6358 to prevent this illegal instruction fault. This is classified as an availability issue (CWE-703 or similar improper exception handling) rather than a code execution or privilege escalation vulnerability (Feedly).

Impact

The primary impact of this vulnerability is a denial of service — specifically, a kernel panic that crashes the system during boot when USB (EHCI/OHCI) devices are present and the kernel is booted from TP1 on BCM6358-based MIPS devices. There is no known confidentiality or integrity impact; the vulnerability is limited to availability of the affected embedded system. Affected devices running vulnerable Linux kernel versions on BCM6358 hardware may be rendered unbootable or unstable (Feedly).

Exploitability

This vulnerability is not remotely exploitable — it is triggered locally during the kernel boot process on specific BCM6358 MIPS hardware with USB peripherals attached. There is no known public exploit code, no evidence of in-the-wild exploitation, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is very low at 0.000240, reflecting minimal exploitation probability (Feedly).

Mitigation and workarounds

The fix is to disable the RAC flush for TP1 in the BCM6358 BMIPS platform code, which has been applied to the Linux kernel stable tree via multiple commits (e.g., 2cdbcff99f15, 47a449ec09b4, 65b723644294, 288c96aa5b55, ab327f8acdf8). Users running affected BCM6358-based MIPS devices should update to a patched kernel version that includes these fixes. As a workaround, booting from TP0 instead of TP1 may avoid the issue, though upgrading the kernel is the recommended solution (Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45699HIGH7.5
  • Linux Debian logoLinux Debian
  • netatalk
NoYesAug 14, 2026
CVE-2026-73051MEDIUM6.3
  • Linux Debian logoLinux Debian
  • rust-actix-http
NoYesAug 14, 2026
CVE-2026-47766MEDIUM5.1
  • Linux Debian logoLinux Debian
  • crun
NoYesAug 14, 2026
CVE-2026-47192LOW2.1
  • Python logoPython
  • kas
NoYesAug 14, 2026
CVE-2026-47191LOW2.1
  • Python logoPython
  • kas
NoYesAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management