漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV) decoder. The decoder does not correctly validate the funct3 field when decoding vsetvli/vsetivli/vsetvl, allowing certain invalid OP-V instruction encodings to be misinterpreted and executed as vset* configuration instructions rather than raising an illegal-instruction exception. This can be exploited by providing crafted RISC-V binaries to cause incorrect trap behavior, architectural state corruption/divergence, and potential denial of service in systems that rely on NEMU for correct execution or sandboxing.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NEMU 安全漏洞
Vulnerability Description
NEMU是XiangShan开源的一个用于教学的全系统模拟器。 NEMU v2025.12.r2之前版本存在安全漏洞,该漏洞源于RISC-V Vector解码器指令验证不当,可能导致特制的二进制文件造成不正确的陷阱行为、架构状态损坏或拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A