CVE-2026-29645Xiangshan · Nemu
Vulnerability data via NVD (ingested)
NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV) decoder. The decoder does not correctly validate the funct3 field when decoding vsetvli/vsetivli/vsetvl, allowing certain invalid OP-V instruction encodings to be misinterpreted and executed as vset* configuration instructions rather than raising an illegal-instruction exception. This can be exploited by providing crafted RISC-V binaries to cause incorrect trap behavior, architectural state corruption/divergence, and potential denial of service in systems that rely on NEMU for correct execution or sandboxing.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-29645product:"Xiangshan Nemu" version:"2025.12"http.html:"Nemu"More intel sources (5)
vuln:CVE-2026-29645vulnerabilities.cve_id: CVE-2026-29645CVE-2026-29645CVE-2026-29645"CVE-2026-29645" exploit -site:nvd.nist.gov