CVE-2026-29646
CVE-2026-29646 is a critical-severity vulnerability with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-267.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 1% (51st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-23958
- Weakness: CWE-267
- Published:
- Last modified:
Description
In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled incorrectly and can influence machine-level interrupt enable state (mie). This breaks privilege/virtualization isolation and can lead to denial of service or privilege-boundary violation in environments relying on NEMU for correct interrupt virtualization.
Frequently asked questions
- What is CVE-2026-29646?
- In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled incorrectly and can influence machine-level interrupt enable state (mie). This breaks privilege/virtualization isolation and can lead to denial of service or privilege-boundary violation in environments relying on NEMU for correct interrupt virtualization.
- How severe is CVE-2026-29646?
- CVE-2026-29646 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-29646 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (51st percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-29646?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2026-29646 have an EU (EUVD) identifier?
- Yes. CVE-2026-29646 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-23958.
- When was CVE-2026-29646 published?
- CVE-2026-29646 was published on 2026-04-20 and last updated on 2026-06-17.
References
- https://docs.riscv.org/reference/isa/priv/hypervisor.html
- https://docs.riscv.org/reference/isa/priv/machine.html
- https://docs.riscv.org/reference/isa/priv/supervisor.html
- https://docs.riscv.org/reference/isa/unpriv/zicsr.html
- https://github.com/OpenXiangShan/NEMU/issues/951
- https://github.com/OpenXiangShan/NEMU/pull/938
- https://github.com/OpenXiangShan/NEMU/pull/938/commits/55295c46580456d8d5a9d5736e1fda924b8825ab
Other CWE-267 vulnerabilities
- CVE-2023-22647 — Critical (CVSS 9.9): An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing…
- CVE-2026-96659 — Critical (CVSS 9.1): A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause…
- CVE-2021-44547 — Critical (CVSS 9.1): A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed…
- CVE-2026-10090 — Critical (CVSS 9.0): A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced…
- CVE-2026-18951 — High (CVSS 8.8): A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly…
- CVE-2026-27314 — High (CVSS 8.8): Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with…