9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled incorrectly and can influence machine-level interrupt enable state (mie). This breaks privilege/virtualization isolation and can lead to denial of service or privilege-boundary violation in environments relying on NEMU for correct interrupt virtualization.
AI Analysis
Privilege/virtualization isolation break due to incorrect handling of VS-mode guest write to supervisor interrupt-enable CSR
Basic Information
ID
CVE-2026-29646
Source
mitre
Published
Apr 20, 2026 at 00:00
Modified
Apr 21, 2026 at 19:50
Affected Product
Vendor
OpenXiangShan
Product
OpenXiangShan NEMU
Version
prior to 55295c4
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
OpenXiangShan
Product
NEMU
Version
prior to 55295c4
References
- docs.riscv.org /reference/isa/priv/machine.html
- github.com /OpenXiangShan/NEMU/issues/951
- github.com /OpenXiangShan/NEMU/pull/938
- github.com /OpenXiangShan/NEMU/pull/938/commits/55295c46580456d8d5a9d5736e1fda924b8825ab
- docs.riscv.org /reference/isa/unpriv/zicsr.html
- docs.riscv.org /reference/isa/priv/supervisor.html
- docs.riscv.org /reference/isa/priv/hypervisor.html