Home

Description

In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled incorrectly and can influence machine-level interrupt enable state (mie). This breaks privilege/virtualization isolation and can lead to denial of service or privilege-boundary violation in environments relying on NEMU for correct interrupt virtualization.

PUBLISHED Reserved 2026-03-04 | Published 2026-04-20 | Updated 2026-04-21 | Assigner mitre

References

docs.riscv.org/reference/isa/priv/machine.html

github.com/OpenXiangShan/NEMU/issues/951

github.com/OpenXiangShan/NEMU/pull/938

github.com/...mmits/55295c46580456d8d5a9d5736e1fda924b8825ab

docs.riscv.org/reference/isa/unpriv/zicsr.html

docs.riscv.org/reference/isa/priv/supervisor.html

docs.riscv.org/reference/isa/priv/hypervisor.html

cve.org (CVE-2026-29646)

nvd.nist.gov (CVE-2026-29646)

Download JSON