CVE-2025-50897 Details
Description
A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly trigger a Store/AMO access fault during store instructions (sd). This occurs despite the presence of proper page table entries and valid memory access modes. The fault is reproducible when transitioning into virtual memory and attempting store operations in mapped kernel memory, indicating a potential flaw in the MMU, PMP, or memory access enforcement logic. This may cause unexpected kernel panics or denial of service in systems using BOOMv1.2.
A vulnerability in the RISC-V BOOM SonicBOOM 1.2 processor implementation has been identified, where valid virtual-to-physical address translations with write permissions in SV39 mode incorrectly trigger a Store/AMO access fault during store instructions. This issue arises despite proper page table entries and valid memory access modes. The fault occurs when transitioning into virtual memory and attempting store operations in mapped kernel memory, suggesting a flaw in the memory management unit, physical memory protection, or memory access enforcement logic. The vulnerability may lead to unexpected kernel panics or denial-of-service conditions in affected systems.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/LuLuji04/POC-Boomv1.2 | [email protected] | ExploitThird Party Advisory |
| https://github.com/riscv-boom/riscv-boom | [email protected] | Product |
| https://github.com/riscv-software-src/riscv-isa-sim | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
| CWE-693 | Protection Mechanism Failure | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| boom-core boomv | 1.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 17, 2025 | Initial Analysis | [email protected] |
| Aug 19, 2025 | CVE Modified | CISA-ADP |
| Aug 19, 2025 | New CVE Received | [email protected] |