CVE-2025-63384
A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified by the sstatus.SPP bit, the processor incorrectly remains in M-mode, leading to a critical privilege retention vulnerability.
Published:Nov 10, 2025
Last Modified:Feb 5, 2026
EPS:Nov 10, 2025
EPSS Score:0.00042
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Chipsalliance
Product
Rocket-chip
Chipsalliance
Rocket-chip
Vendor
Chipsalliance
Product
Rocketchip
Chipsalliance
Rocketchip
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
