Impact
An output mismatch between the RTL model and the synthesized netlist of the openRISC OR1200 CPU core can cause unpredictable data on the CPU output port, leading to erratic behavior and potential system instability. The weakness is identified as CWE‑116, improper handling of data boundaries.
Affected Systems
The vulnerability affects any deployment of the openRISC OR1200 core that uses the unpatched RTL and netlist combination prior to commit 83ac6b. Systems built from source with the legacy RTL/netlist, or that rely on pre‑built binaries derived from that version, are impacted.
Risk and Exploitability
With a CVSS score of 9.1, the vulnerability is considered high severity, yet its EPSS score of < 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack scenario, as inferred from the description, involves a software or firmware component that can supply custom instruction streams to the CPU in order to trigger the RTL/netlist mismatch and produce unpredictable outputs.
OpenCVE Enrichment