CVE-2026-29646 Details
Description
In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled incorrectly and can influence machine-level interrupt enable state (mie). This breaks privilege/virtualization isolation and can lead to denial of service or privilege-boundary violation in environments relying on NEMU for correct interrupt virtualization.
A vulnerability exists in OpenXiangShan NEMU versions prior to 55295c4, when the RVH (Hypervisor extension) is enabled. In this scenario, a virtual supervisor (VS-mode) guest can incorrectly write to the supervisor interrupt-enable CSR (sie), which may unintentionally affect the machine-level interrupt enable state (mie). This mismanagement disrupts proper privilege and virtualization isolation, potentially leading to a denial-of-service condition or a violation of privilege boundaries in environments that depend on NEMU for accurate interrupt virtualization.
Users can update to the latest version of OpenXiangShan NEMU, where this issue has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 20, 2026CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.riscv.org/reference/isa/priv/hypervisor.html | [email protected] | Not Applicable |
| https://docs.riscv.org/reference/isa/priv/machine.html | [email protected] | |
| https://docs.riscv.org/reference/isa/priv/supervisor.html | [email protected] | Not Applicable |
| https://docs.riscv.org/reference/isa/unpriv/zicsr.html | [email protected] | Not Applicable |
| https://github.com/OpenXiangShan/NEMU/issues/951 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/OpenXiangShan/NEMU/pull/938 | [email protected] | Issue TrackingVendor |
| https://github.com/OpenXiangShan/NEMU/pull/938/commits/55295c46580456d8d5a9d5736e1fda924b8825ab | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-267 | Privilege Defined With Unsafe Actions | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| OpenXiangShan NEMU | >= 55295c4, < 55295c4-D81 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | New CVE Received | [email protected] |
Volerion