CVE-2026-29649
קריטית 9.8
תיאור (מקור, אנגלית)
NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectly masked/updated based on menvcfg[7:4], so a machine-mode write to menvcfg can implicitly modify the hypervisor's environment configuration. This can lead to incorrect enforcement of virtualization configuration and may cause unexpected traps or denial of service when executing cache-block management instructions in virtualized contexts (V=1).
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 000) נכון ל-25/9/2026
- CWE
- CWE-693
מוצרים מושפעים
xiangshan: nemu
קישורים
- https://github.com/OpenXiangShan/NEMU/pull/689 Issue TrackingPatch
- https://docs.riscv.org/reference/isa/priv/hypervisor.html Product
- https://docs.riscv.org/reference/isa/priv/machine.html Product
- https://github.com/OpenXiangShan/NEMU/issues/681 Issue Tracking