CVE-2026-29647

In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even when mstateen0.IMSIC is cleared, potentially enabling cross-context information leakage or disruption of interrupt handling.
Configurations

No configuration.

History

No history.

Information

Published : 2026-04-20 21:16

Updated : 2026-06-17 10:29


NVD link : CVE-2026-29647

Mitre link : CVE-2026-29647

CVE.ORG link : CVE-2026-29647


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management