Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-53658

20
FAUCET Score

CVE-2023-53658 is a null pointer dereference vulnerability in the Linux kernel's Broadcom QSPI driver (bcm-qspi). It occurs when the driver attempts to unregister an SPI master after failing to find necessary resources, leading to a system crash. Rated Medium severity (CVSS 5.5), this flaw requires local access and low privileges to exploit, resulting in a high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.9, < 4.14.322CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.291CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.251CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.188CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.121CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 25th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2023-53658

kernel: spi: bcm-qspi: return error if neither hif_mspi nor mspi is available

Oct 7, 2025

References

git.kernel.org / stable/c/217b6ea8cf7b819477bca597a6ae2d43d38ba283
Patch
git.kernel.org / stable/c/22ae32d80ef590d12a2364e4621f90f7c58445c7
Patch
git.kernel.org / stable/c/32b9c8f7892c19f7f5c9fed5fb410b9fd5990bb6
Patch
git.kernel.org / stable/c/398e6a015877d44327f754aeb48ff3354945c78c
Patch
git.kernel.org / stable/c/7c1f23ad34fcdace50275a6aa1e1969b41c6233f
Patch
git.kernel.org / stable/c/a91c34357afcfaa5307e254f22a8452550a07b34
Patch
git.kernel.org / stable/c/d20db3c58a7f9361e370a7850ceb60dbdf62eea3
Patch
git.kernel.org / stable/c/d3dcdb43c872a3b967345144151a2c9bb9124c9b
Patch