Περιγραφή
NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectly masked/updated based on menvcfg[7:4], so a machine-mode write to menvcfg can implicitly modify the hypervisor-s environment configuration. This can lead to incorrect enforcement of virtualization configuration and may cause unexpected traps or denial of service when executing cache-block management instructions in virtualized contexts (V=1).
CVSS 9.8EPSS 0.44799999999999995%Κίνδυνος 1.02
Προβολή πηγής- Δημοσίευση
- 2026-04-20 20:16:48
- Επηρεαζόμενες εκδόσεις
- unknown
- Τύπος
- Υλικολογισμικό
- Διάνυσμα
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H