VendorsOpen HW Groupcva6all versions
Vulnerabilities

Open HW Group CVA6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2022-34635
The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field is set to Dirty.
Published 2022-07-18 · Modified
9.8EPSS 0.009
CVE-2022-33021
CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30.
Published 2022-06-29 · Modified
7.5EPSS 0.011
CVE-2022-33023
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.
Published 2022-06-29 · Modified
7.5EPSS 0.007
CVE-2022-34641
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occurs during address translation.
Published 2022-07-18 · Modified
5.5EPSS 0.003
CVE-2022-34639
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a treats non-standard fence instructions as illegal which can affect the function of the application.
Published 2022-07-18 · Modified
5.5EPSS 0.002
CVE-2022-34633
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted sfence.vma instructions rather create an exception.
Published 2022-07-18 · Modified
5.5EPSS 0.002
CVE-2022-34634
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a executes crafted or incorrectly formatted det instructions rather create an exception.
Published 2022-07-18 · Modified
5.5EPSS 0.002
CVE-2022-34636
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMA violation occurs during address translation.
Published 2022-07-18 · Modified
5.5EPSS 0.002
CVE-2022-34637
CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a implements an incorrect exception type when an illegal virtual address is loaded.
Published 2022-07-18 · Modified
5.5EPSS 0.002
CVE-2022-34640
The *tval of ecall/ebreak in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a was discovered to be incorrect.
Published 2022-07-18 · Modified
5.5EPSS 0.002