Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openxiangshan
Openxiangshan nemu |
|
| Vendors & Products |
Openxiangshan
Openxiangshan nemu |
Wed, 22 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Improper CSRs Access in OpenXiangShan NEMU |
Wed, 22 Apr 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Improper CSR Access Control in OpenXiangShan NEMU | |
| Weaknesses | CWE-284 |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
cvssV3_1
|
Tue, 21 Apr 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Improper CSR Access Control in OpenXiangShan NEMU | |
| Weaknesses | CWE-284 |
Mon, 20 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcfg and senvcfg. As a result, less-privileged code may read or write these CSRs without the required exception, potentially bypassing intended state-enable based isolation controls in virtualized or multi-privilege environments. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-21T19:50:38.197Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-29648
Updated: 2026-04-21T18:51:42.611Z
Status : Deferred
Published: 2026-04-20T21:16:19.733
Modified: 2026-04-21T20:16:40.877
Link: CVE-2026-29648
No data.
OpenCVE Enrichment
Updated: 2026-04-28T09:26:43Z