PT-2026-33855 · Xiangshan · Xiangshan

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-29643

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions XiangShan versions prior to commit edb1dfaf7d290ae99724594507dc46c2c2125384
Description An improper exceptional-condition handling flaw exists in the CSR subsystem (NewCSR). Certain sequences of CSR operations targeting non-existent or custom CSR addresses may trigger an illegal-instruction exception but fail to reliably transfer control to the configured trap handler mtvec. This results in control-flow disruption and may leave the core in a hung or unrecoverable state, allowing a local attacker with code execution capabilities to cause a denial of service and potentially an inconsistent architectural state.
Recommendations Update to commit edb1dfaf7d290ae99724594507dc46c2c2125384 or a newer version.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-29643

Affected Products

Xiangshan