CVE-2026-29645Disclosure(xiangshan / nemu)

LOWCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for xiangshan nemu systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV) decoder. The decoder does not correctly validate the funct3 field when decoding vsetvli/vsetivli/vsetvl, allowing certain invalid OP-V instruction encodings to be misinterpreted and executed as vset* configuration instructions rather than raising an illegal-instruction exception. This can be exploited by providing crafted RISC-V binaries to cause incorrect trap behavior, architectural state corruption/divergence, and potential denial of service in systems that rely on NEMU for correct execution or sandboxing.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-131CWE-1287

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nemu

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
nemu

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-21: 3Active Exploitation · 2026-04-21: 1Technical Details · 2026-04-21: 204-21
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-29645 NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV) decoder. The decoder does not correctly valid… https://www.cve.org/CVERecord?id=CVE-2026-29645

    Post summary

    CVE-2026-29645 is an improper instruction‑validation flaw in NEMU's RISC‑V Vector decoder; the post is a disclosure of the vulnerability without evidence of exploitation or mitigation.

    00010128
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29645 NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV) decoder. The decoder does not correctly valid… https://www.cve.org/CVERecord?id=CVE-2026-29645 ----- Traducción: CVE-2026-29645 NEM… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-29645, noting an improper instruction‑validation flaw in NEMU's RVV decoder, with no mention of PoC, exploit code, active exploitation, or patch details.

    0000028
    72 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting NEMU (CVE-2026-29645) https://vuldb.com/vuln/358354/cti

    Post summary

    The post indicates increased actor targeting of NEMU via CVE-2026-29645, suggesting active exploitation in the wild.

    0000043
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxiangshannemu2025.12--

Explore more