Boom-core

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    4
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-50897

    A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly trigger a Store/AMO access fault during store instructions (sd). This occurs despite the presence of proper page table entries and valid memory access modes. The fault is reproducible when transitioning into virtual memory and attempting store operations in mapped kernel memory, indicating a potential flaw in the MMU, PMP, or memory access enforcement logic. This may cause unexpected kernel panics or denial of service in systems using BOOMv1.2.

    Last Modified: Oct 17, 2025
    Published: Aug 19, 2025

    CVE-2025-8774

    riscv-boom SonicBOOM L1 Data Cache timing discrepancy

    Last Modified: Sep 16, 2025
    Published: Aug 09, 2025

    CVE-2022-34641

    CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a and RISCV-Boom commit ad64c5419151e5e886daee7084d8399713b46b4b implements the incorrect exception type when a PMP violation occurs during address translation.

    Last Modified: Nov 21, 2024
    Published: Jul 18, 2022

    CVE-2022-26296

    BOOM: The Berkeley Out-of-Order RISC-V Processor commit d77c2c3 was discovered to allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

    Last Modified: Nov 21, 2024
    Published: Mar 28, 2022

    CVE-2020-29561

    An issue was discovered in SonicBOOM riscv-boom 3.0.0. For LR, it does not avoid acquiring a reservation in the case where a load translates successfully but still generates an exception.

    Last Modified: Nov 21, 2024
    Published: Dec 04, 2020
    Items Per Page
    Boom-Core Vulnerabilities & Security CVEs | CVE-DB