PT-2026-33830 · Nemu · Nemu

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-29649

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NEMU (affected versions not specified)
Description An implementation flaw exists in the RISC-V Hypervisor CSR handling. The henvcfg[7:4] fields, which relate to CBIE, CBCFE, and CBZE, are incorrectly masked or updated based on menvcfg[7:4]. Consequently, a machine-mode write to menvcfg can implicitly modify the hypervisor environment configuration. This may result in incorrect enforcement of virtualization configuration, potentially causing unexpected traps or denial of service during the execution of cache-block management instructions in virtualized contexts where V=1.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2026-29649

Affected Products

Nemu