What is CVE-2026-71694?
This vulnerability exists in the Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2. A remote attacker can achieve arbitrary code execution by exploiting the CSR trap-return state restoration logic, MRET handling logic, mstatus.MPRV update path, and CSRFile logic in ProcessorFuzz BO. Users are advised to discontinue use of this benchmark version or await a patch.
Azərbaycanca: Bu zəiflik Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2-də aşkar edilib. Uzaqdan hücum edən şəxs CSR trap-return state restoration, MRET handling logic, mstatus.MPRV update path və ProcessorFuzz BO-dakı CSRFile məntiqi vasitəsilə ixtiyari kod icrası həyata keçirə bilər. Məhsulun istifadəçilərinə bu benchmark versiyasını dayandırmaq və ya yamaq gözləmək tövsiyə olunur.
FAQ2
Which product is affected by vulnerability CVE-2026-71694?
This vulnerability exists in the Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark version v1.2.
What can an attacker achieve by exploiting CVE-2026-71694?
A remote attacker can achieve arbitrary code execution by exploiting the CSR trap-return state restoration logic, MRET handling logic, mstatus.MPRV update path, and CSRFile logic.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.