chipsalliance/rocket-chip
cpe:2.3:a:linuxfoundation:rocket_chip_generator:*:*:*:*:*:*:*
A vulnerability exists in the Open-Source RISC-V Processor, specifically in the Rocket Chip repository, commit f517abb. The issue arises from improper retention of the mstatus.SUM bit, which remains non-zero, violating privileged specification constraints. This flaw could enable physical memory access attacks.
Exploitation of this vulnerability could lead to unauthorized physical memory access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.