Description
An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return state restoration logic, MRET handling logic, mstatus.MPRV update path, CSRFile logic in ProcessorFuzz BOOM benchmark Benchmarks/Verilog/SmallBoomTile_v1.2_state.v
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability originates in the CSR trap-return state restoration logic of the BOOM Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2, where manipulation of MRET handling, the mstatus.MPRV update path, and CSRFile logic allows an attacker to inject arbitrary machine-mode instructions. This flaw grants full machine-level privileges, enabling execution of any code and thus a complete compromise of the processor platform.

Affected Systems

It affects implementations that instantiate the BOOM RTL benchmark v1.2 at revision 2d08d0d8b4563212175212f9db0e69f6e68c9619. Systems that embed this design include custom SoCs, simulators, or any platform running the ProcessorFuzz Benchmarks/Verilog/SmallBoomTile_v1.2_state.v test harness. No vendor patch is listed, and affected parties should look for community fixes or updates to the BOOM repository.

Risk and Exploitability

Because the flaw allows arbitrary code execution at the highest privilege level, the potential damage is severe. The CVSS score is 8.8, categorizing it as highly severe. The EPSS score is <1%, indicating a very low but non-zero likelihood of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via remote manipulation of CSR values; based on the description, it is inferred that an attacker could trigger exploitation by sending malformed CSR inputs that traverse the MRET handling path during state restoration.

Generated by OpenCVE AI on August 24, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any updated RTL or firmware releases from the BOOM community that address the CSR trap-return logic flaw; if none are available, consider replacing or patching the affected components with a corrected implementation that enforces proper mstatus.MPRV updates and protects MRET handling.
  • Implement a runtime safeguard that intercepts CSR writes affecting MPRV or trap-return state: reject or sanitize unexpected values to prevent privilege escalation.
  • Monitor system logs for abnormal CSR activity and audit firmware integrity to detect potential exploitation attempts.

Generated by OpenCVE AI on August 24, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via CSR Trap-Return Logic in BOOM Benchmark

Mon, 24 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Faulty CSR Trap-Return Logic in BOOM RTL
Weaknesses CWE-269
CWE-676

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 21 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Riscv-boom
Riscv-boom boom
Vendors & Products Riscv-boom
Riscv-boom boom

Thu, 20 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Faulty CSR Trap-Return Logic in BOOM RTL
Weaknesses CWE-269
CWE-676

Thu, 20 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Faulty CSR Trap-Return Logic in BOOM RISC-V Processor
Weaknesses CWE-264
CWE-732

Wed, 19 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Faulty CSR Trap-Return Logic in BOOM RISC-V Processor
Weaknesses CWE-264
CWE-732

Wed, 19 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return state restoration logic, MRET handling logic, mstatus.MPRV update path, CSRFile logic in ProcessorFuzz BOOM benchmark Benchmarks/Verilog/SmallBoomTile_v1.2_state.v
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-24T19:55:23.543Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71694

cve-icon Vulnrichment

Updated: 2026-08-24T19:55:16.652Z

cve-icon NVD

Status : Received

Published: 2026-08-19T14:17:39.333

Modified: 2026-08-24T20:17:14.007

Link: CVE-2026-71694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T00:00:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)