Impact
An issue was found in the openRISC OR1200 processor where the program counter is updated incorrectly when special purpose registers (SPR) change, potentially causing the device to hang or become unresponsive. The flaw does not provide an attack path for code execution or data exfiltration; its primary consequence is a loss of availability for the affected system. The weakness is an example of an incorrect calculation or handling of data.
Affected Systems
The vulnerability resides in the openRISC OR1200 architecture, specifically within the code identified by commit 83ac6b. Any deployments of the OR1200 processor or emulation that have not been updated past this commit may be affected. No official vendor or product name is listed, so protection applies to all instances that incorporate the vulnerable code.
Risk and Exploitability
No CVSS score or EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, indicating limited documented exploitation. The flaw requires the ability to trigger a change to an SPR and to observe the resulting incorrect PC update; this may limit the attack vector to local or privileged contexts unless a remote interface to modify SPR exists. The potential impact remains a denial of service, but lack of exploitation evidence suggests a moderate overall risk pending further information.
OpenCVE Enrichment