Openhwgroup's vulnerability profile centers on the CVA6 processor core, an open-source RISC-V design that occupies a specialized but strategically important position in the processor landscape as a reference and integration target for custom silicon implementations. The recurring weakness classes—improper exception handling, default permission issues, and boundary-condition weaknesses—reflect the architectural and configuration complexities inherent in CPU design and hardware description language codebases. Defenders working with custom or embedded processors derived from CVA6 should review disclosed issues against their integration points and toolchains; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openhwgroup over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34635CRITICAL The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field is set to Dirty. | Jul 18, 2022 | 9.8 | 26 | NO | NO |
CVE-2022-33023HIGH CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong. | Jun 29, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-34641MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occ | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-34639MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standard fence instructions as illegal which can affect the function of the application. | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-34637MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an incorrect exception type when an illegal virtual address is loaded. | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-34636MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMA violation occ | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-34634MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception. | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-33021HIGH CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30. | Jun 29, 2022 | 7.5 | 19 | NO | NO |
CVE-2022-34640MEDIUM The *tval of ecall/ebreak in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a was discovered to be incorrect. | Jul 18, 2022 | 5.5 | 18 | NO | NO |
CVE-2022-34633MEDIUM CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception. | Jul 18, 2022 | 5.5 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openhwgroup.
Media articles that mention a CVE ID that affects a product developed by Openhwgroup — matched by CVE ID, not by vendor name.