Boom Core maintains a narrowly scoped set of RISC-V related products, including variants such as RISVC_BOOM and BOOMV, that serve specialized processor design and verification roles. The vendor's disclosed vulnerabilities reflect this focused application domain; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boom Core over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26296MEDIUM BOOM: The Berkeley Out-of-Order RISC-V Processor commit d77c2c3 was discovered to allow unauthorized disclosure of information to an attacker with local user access via a side-chan | Mar 28, 2022 | 5.5 | 20 | NO | NO |
CVE-2020-29561MEDIUM An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case where a load translates successfully but still generates an exc | Dec 4, 2020 | 5.5 | 20 | NO | NO |
CVE-2025-8774MEDIUM A vulnerability has been found in riscv-boom SonicBOOM up to 2.2.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component L1 Dat | Aug 9, 2025 | 4.7 | 19 | NO | NO |
CVE-2022-34641MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occ | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2025-50897MEDIUM A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_ | Aug 19, 2025 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boom Core.
Media articles that mention a CVE ID that affects a product developed by Boom Core — matched by CVE ID, not by vendor name.