CVE-2026-29647

In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even when mstateen0.IMSIC is cleared, potentially enabling cross-context information leakage or disruption of interrupt handling.
Configurations

No configuration.

History

21 Apr 2026, 20:16

Type Values Removed Values Added
References () https://github.com/OpenXiangShan/NEMU/issues/691 - () https://github.com/OpenXiangShan/NEMU/issues/691 -
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

20 Apr 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-20 21:16

Updated : 2026-04-21 20:16


NVD link : CVE-2026-29647

Mitre link : CVE-2026-29647

CVE.ORG link : CVE-2026-29647


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management