
CVE-2026-29647 In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state via stopei/vstopei CSRs even when http://mstateen0.IM… https://www.cve.org/CVERecord?id=CVE-2026-29647
Post summary
The post announces that CVE‑2026‑29647 in OpenXiangShan NEMU is a permission‑elevation flaw permitting lower‑privileged code to read IMSIC state through certain CSRs.

