CNNVD-202508-843 Information

CNNVD ID

CNNVD-202508-843

CVE-2025-8774

  • CNNVD Published: 2025-08-09

Description (Chinese)

riscv-boom SonicBOOM是BOOM: The Berkeley Out-of-Order RISC-V Processor开源的一个SonicBOOM:伯克利混乱机器。 riscv-boom SonicBOOM 2.2.3及之前版本存在安全漏洞,该漏洞源于组件L1 Data Cache Handler存在可观察的时间差异问题。

Description (English)

riscv-boom SonicBOM is a SonicBOM: Berkeley Chaos Machine. There is a security loophole in the riscv-boom SonicBOM 2.2.3 and earlier versions, which stems from observed time differences in component L1 Data Cache Handler.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

BOOM: The Berkeley Out-of-Order RISC-V Processor

Published

2025-08-09

Last Modified

2026-02-24

References

https://vuldb.com/?ctiid.319297 https://vuldb.com/?submit.625550 https://vuldb.com/?id.319297 https://github.com/fizz-is-on-the-way/vuls_cpu/tree/master/MSHRush https://access.redhat.com/security/cve/cve-2025-8774

Patch

https://github.com/riscv-boom/riscv-boom/releases

Share on: