HIGHVulnerability

CVE-2026-67846

Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read and write permission logic without an explicit local satp.MODE validity check at the use site

Properties

severity
HIGH
score
7.8
epss_score
0.00171
cve_id
CVE-2026-67846
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-18T18:19:25.240
last_modified
2026-09-09T16:04:24.933
epss_percentile
0.06711

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Incorrect Privilege Assignment

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-67846 — Ninja Signal Threat Intelligence | Ninja Signal