OVERVIEW CVE-2026-29644 affects XiangShan, an open-source high-performance RISC-V processor, in versions subsequent to commit edb1dfaf7d (November 28, 2024). The vulnerability stems from improper gating of the distributed Control and Status Register (CSR) write-enable path, which fails to properly block illegal CSR write attempts targeting custom Physical Memory Attribute (PMA) configuration state. This design flaw violates RISC-V privileged specification requirements that mandate illegal-instruction exceptions for non-existent or illegal CSR accesses. SEVERITY The vulnerability carries a CVSS 3.1 score of 5.3 (MEDIUM) with a local attack vector requiring low complexity and low privileges. An attacker must execute code on the affected processor core to exploit the flaw. Successful exploitation allows tampering with memory-attribute enforcement mechanisms, potentially enabling privilege escalation, unauthorized information disclosure, or denial of service depending on how the target platform integrates PMA for security and isolation boundaries. The EPSS score of 0.00011 indicates this vulnerability currently ranks among the lowest-probability threats relative to the broader CVE population. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, with the vulnerability absent from the CISA Known Exploited Vulnerabilities (KEV) catalog and marked as inactive on exploit tracking lists. No public exploit code has been identified. Community attention remains limited given the vulnerability's narrow scope of affecting primarily research and development deployments of the open-source XiangShan processor rather than commercial production systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.