CVE-2026-29644
Last modified
CVE-2026-29644 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) has improper gating of its distributed CSR write-enable path, allowing illegal CSR write attempts to alter custom PMA (Physical Memory Attribute) CSR state. Though the RISC-V privileged specification requires an illegal-instruction exception for non-existent/illegal CSR accesses, affected XiangShan versions may still propagate such writes to replicated PMA configuration state. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) has improper gating of its distributed CSR write-enable path, allowing illegal CSR write attempts to alter custom PMA (Physical Memory Attribute) CSR state. Though the RISC-V privileged specification requires an illegal-instruction exception for non-existent/illegal CSR accesses, affected XiangShan versions may still propagate such writes to replicated PMA configuration state. Local attackers able to execute code on the core (privilege context depends on system integration) can exploit this to tamper with memory-attribute enforcement, potentially leading to privilege escalation, information disclosure, or denial of service depending on how PMA enforces platform security and isolation boundaries.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-29644?
How severe is CVE-2026-29644?
How do I fix CVE-2026-29644?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2962A vulnerability was found in D-Link DWR-M960 1.01.07. This v…8.8
- CVE-2026-29628A stack overflow in the experimental/tinyobj_loader_opt.h fi…6.2
- CVE-2026-2963A vulnerability was determined in Jinher OA C6 up to 2026021…6.3
- CVE-2026-2964A vulnerability was identified in higuma web-audio-recorder-…9.8
- CVE-2026-29642A local attacker who can execute privileged CSR operations (…7.8
- CVE-2026-29643XiangShan (Open-source high-performance RISC-V processor) co…7.1
- CVE-2026-29645NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an imp…7.5
- CVE-2026-29646In OpenXiangShan NEMU prior to 55295c4, when running with RV…9.8
- CVE-2026-29647In OpenXiangShan NEMU, insufficient Smstateen permission enf…6.5
- CVE-2026-29648In OpenXiangShan NEMU, when Smstateen is enabled, clearing m…8.8
- CVE-2026-29649NEMU contains an implementation flaw in its RISC-V Hyperviso…9.8
- CVE-2026-2965A security flaw has been discovered in 07FLYCMS, 07FLY-CMS a…2.4
Are you affected by CVE-2026-29644?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
