Execution disruption via malformed DRET acceptance
Published Jul 18, 2022 · Updated Aug 3, 2024
Improper exception handling in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a allows local users to disrupt execution. The decoder overwrites the existing illegal-instruction result while checking Debug Mode, so a DRET encoding with a nonzero rd field executes instead of trapping. Reachability requires local code execution in Debug Mode; the demonstrated outcome is divergent control flow rather than an illegal-instruction trap.
Summary
What happened
Improper exception handling in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a allows local users to disrupt execution. The decoder overwrites the existing illegal-instruction result while checking Debug Mode, so a DRET encoding with a nonzero rd field executes instead of trapping. Reachability requires local code execution in Debug Mode; the demonstrated outcome is divergent control flow rather than an illegal-instruction trap.
The record
- CVE
- CVE-2022-34634
- Published
- Jul 18, 2022
- Updated
- Aug 3, 2024
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-755
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Jul 18, 2022CVE publishedPublication date reported by the CVE source.
- Aug 3, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Invalid DRET instruction test caseproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo