Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-29643

24
FAUCET Score

OVERVIEW CVE-2026-29643 is an improper exception handling vulnerability in XiangShan, an open-source high-performance RISC-V processor, affecting versions from commit edb1dfaf7d290ae99724594507dc46c2c2125384 dated 2024-11-28. The flaw exists within the CSR (Control and Status Register) subsystem where certain sequences of CSR operations targeting non-existent or custom CSR addresses fail to reliably transfer control to the configured trap handler, potentially causing the processor core to enter a hung or unrecoverable state. SEVERITY This vulnerability carries a CVSS score of 7.1 (HIGH) with a local attack vector requiring low complexity and low privilege requirements. The attack involves no user interaction and impacts the integrity and availability of the affected system. While the confidentiality impact is minimal, the potential for high integrity compromise and denial of service through control-flow disruption and architectural state inconsistency makes this a significant concern for systems utilizing the affected XiangShan processor. EXPLOITATION STATUS There is no evidence of active exploitation or public exploit code availability. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on industry hot lists. However, the extremely low EPSS score of 0.000120000 and FAUCET risk score of 37.0/100 suggest minimal current real-world exploitation risk, though organizations deploying XiangShan-based systems should prioritize patching to address the local denial of service and processor stability concerns.

Impacted Technologies

VendorProductVersion(s)CPE
N/AN/A
n/aCNA affected

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
6.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 26th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

docs.riscv.org / reference/isa/priv/machine.html
docs.riscv.org / reference/isa/priv/priv-csrs.html
github.com / OpenXiangShan/XiangShan/issues/3959
github.com / OpenXiangShan/XiangShan/pull/3966