Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g435-j3hg-9vfh

Опубликовано: 10 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified by the sstatus.SPP bit, the processor incorrectly remains in M-mode, leading to a critical privilege retention vulnerability.

A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified by the sstatus.SPP bit, the processor incorrectly remains in M-mode, leading to a critical privilege retention vulnerability.

EPSS

Процентиль: 13%
0.00042
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified by the sstatus.SPP bit, the processor incorrectly remains in M-mode, leading to a critical privilege retention vulnerability.

EPSS

Процентиль: 13%
0.00042
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266