Description
An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial of Service (DoS).
Published: 2026-08-26
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue was found in the openRISC OR1200 processor where the program counter is updated incorrectly when special purpose registers (SPR) change, potentially causing the device to hang or become unresponsive. The flaw does not provide an attack path for code execution or data exfiltration; its primary consequence is a loss of availability for the affected system. The weakness is an example of an incorrect calculation or handling of data.

Affected Systems

The vulnerability resides in the openRISC OR1200 architecture, specifically within the code identified by commit 83ac6b. Any deployments of the OR1200 processor or emulation that have not been updated past this commit may be affected. No official vendor or product name is listed, so protection applies to all instances that incorporate the vulnerable code.

Risk and Exploitability

No CVSS score or EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, indicating limited documented exploitation. The flaw requires the ability to trigger a change to an SPR and to observe the resulting incorrect PC update; this may limit the attack vector to local or privileged contexts unless a remote interface to modify SPR exists. The potential impact remains a denial of service, but lack of exploitation evidence suggests a moderate overall risk pending further information.

Generated by OpenCVE AI on August 26, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the openRISC OR1200 firmware or emulator to a release that has removed the faulty program counter update logic (commit after 83ac6b).
  • Restrict or eliminate privileged interfaces that allow modification of special purpose registers; isolate the device from untrusted traffic that could trigger such changes.
  • Implement monitoring (e.g., watchdog timers) to detect processor stalls or hangs and automatically reset or reboot the device when an outage is detected.

Generated by OpenCVE AI on August 26, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Denial‑of‑Service via Inaccurate Program Counter Update in openRISC OR1200
Weaknesses CWE-682

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Openrisc
Openrisc or1200
Vendors & Products Openrisc
Openrisc or1200

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial of Service (DoS).
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-26T20:40:13.715Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-51675

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T21:16:37.430

Modified: 2026-08-26T21:16:37.430

Link: CVE-2025-51675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:15:05Z

Weaknesses