CVE-2025-63384: Chipsalliance Rocketchip
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exception Return) instruction fails to correctly transition the processor's privilege level. Instead of downgrading from Machine-mode (M-mode) to Supervisor-mode (S-mode) as specified by the sstatus.SPP bit, the processor incorrectly remains in M-mode, leading to a critical privilege retention vulnerability.
Affected products
- Chipsalliance Rocketchip: up to and including 1.6
Published 2025-11-10. Last modified 2026-06-17.