Vulnerability Description
In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even when mstateen0.IMSIC is cleared, potentially enabling cross-context information leakage or disruption of interrupt handling.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://docs.riscv.org/reference/isa/priv/smstateen.html#state-enable-0-register
- https://github.com/OpenXiangShan/NEMU/issues/691
- https://github.com/OpenXiangShan/XiangShan/pull/3978
- https://github.com/OpenXiangShan/NEMU/issues/691
FAQ
What is CVE-2026-29647?
CVE-2026-29647 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even when mstateen0.IMSIC is cleared, potentially enabli...
How severe is CVE-2026-29647?
CVE-2026-29647 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29647?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.