OpenXiangShan NEMU Smstateen Extension Access Control Vulnerability

Vulnerability

A vulnerability exists in OpenXiangShan NEMU related to the Smstateen extension. When Smstateen is enabled, the 'ENVCFG' bit in the 'mstateen0' register does not properly control access to the 'henvcfg' and 'senvcfg' control and status registers (CSRs). This oversight allows less-privileged code to read from or write to these CSRs without the necessary exceptions, potentially circumventing state-enable isolation controls in virtualized or multi-privilege environments.

Impact

Exploitation of this vulnerability could lead to unauthorized access to certain CSRs, allowing less-privileged code to bypass intended isolation controls in virtualized or multi-privilege environments.

Reproduction

To reproduce this vulnerability, first ensure that the Smstateen extension is enabled. Then, clear the 'ENVCFG' bit in the 'mstateen0' register and set the environment to mode=1. After this, attempt to access the 'senvcfg' or 'henvcfg' registers. The access should trigger an illegal instruction exception, but due to the vulnerability, it will not.

Remediation

The issue has been fixed in the OpenXiangShan repository. Users should update to the latest version.

Added: Apr 20, 2026, 9:32 PM
Updated: Apr 20, 2026, 9:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
4.3
remediation
0.0
relevance
6.3
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.