Impact
The vulnerability originates in the CSR trap-return state restoration logic of the BOOM Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2, where manipulation of MRET handling, the mstatus.MPRV update path, and CSRFile logic allows an attacker to inject arbitrary machine-mode instructions. This flaw grants full machine-level privileges, enabling execution of any code and thus a complete compromise of the processor platform.
Affected Systems
It affects implementations that instantiate the BOOM RTL benchmark v1.2 at revision 2d08d0d8b4563212175212f9db0e69f6e68c9619. Systems that embed this design include custom SoCs, simulators, or any platform running the ProcessorFuzz Benchmarks/Verilog/SmallBoomTile_v1.2_state.v test harness. No vendor patch is listed, and affected parties should look for community fixes or updates to the BOOM repository.
Risk and Exploitability
Because the flaw allows arbitrary code execution at the highest privilege level, the potential damage is severe. The CVSS score is 8.8, categorizing it as highly severe. The EPSS score is <1%, indicating a very low but non-zero likelihood of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via remote manipulation of CSR values; based on the description, it is inferred that an attacker could trigger exploitation by sending malformed CSR inputs that traverse the MRET handling path during state restoration.
OpenCVE Enrichment