CVE-2026-29648 Details
Description
In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, less-privileged code may read or write these CSRs without the required exception, potentially bypassing intended state-enable based isolation controls in virtualized or multi-privilege environments.
A vulnerability exists in OpenXiangShan NEMU related to the Smstateen extension. When Smstateen is enabled, the 'ENVCFG' bit in the 'mstateen0' register does not properly control access to the 'henvcfg' and 'senvcfg' control and status registers (CSRs). This oversight allows less-privileged code to read from or write to these CSRs without the necessary exceptions, potentially circumventing state-enable isolation controls in virtualized or multi-privilege environments.
The issue has been fixed in the OpenXiangShan repository. Users should update to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 20, 2026CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/OpenXiangShan/NEMU/issues/690 | CISA-ADP | Issue TrackingTechnical DescriptionVendor |
| https://docs.riscv.org/reference/isa/priv/smstateen.html | [email protected] | |
| https://github.com/OpenXiangShan/NEMU/issues/690 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/OpenXiangShan/XiangShan/pull/3978 | [email protected] | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| OpenXiangShan NEMU | All versions |
CPE
Remediation
| |
| RISC-V Smstateen | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | New CVE Received | [email protected] |
Volerion