PT-2023-12363 · Or1200 · Or1200

Published

2023-04-18

·

Updated

2023-04-27

·

CVE-2021-40506

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OR1200 (aka OpenRISC 1200) processor versions 2011-09-10 through 2015-11-11
Description An issue in the ALU unit of the processor causes the overflow flag not to be updated for the msb and mac instructions, resulting in an incorrect value in the overflow flag. This can lead to corruption in execution for any software that relies on this flag.
Recommendations For versions 2011-09-10 through 2015-11-11, consider modifying software to not rely on the overflow flag for the msb and mac instructions until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-40506

Affected Products

Or1200