RISC-V maintains a narrowly scoped portfolio centered on instruction-set architecture specifications and reference implementations, including the Spike ISA simulator, which serves as a reference tool for RISC-V development and validation. The observed vulnerability signal clusters around improper exception handling and incomplete specification documentation rather than broad product deployment, reflecting the role of these tools in the architecture ecosystem. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Riscv over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1104CRITICAL The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) register that may lead to a vulnerability due to the initial stat | Aug 13, 2021 | 9.8 | 32 | NO | NO |
CVE-2022-34643MEDIUM RISCV ISA Sim commit ac466a21df442c59962589ba296c702631e041b5 implements the incorrect exception priotrity when accessing memory. | Jul 18, 2022 | 5.5 | 19 | NO | NO |
CVE-2022-34642MEDIUM The component mcontrol.action in RISCV ISA Sim commit ac466a21df442c59962589ba296c702631e041b5 contains the incorrect mask which can cause a Denial of Service (DoS). | Jul 18, 2022 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Riscv.
Media articles that mention a CVE ID that affects a product developed by Riscv — matched by CVE ID, not by vendor name.