L1 Data Cache Handler Vulnerability in riscv-boom by Unknown Vendor
CVE-2025-8774
2LOW
What is CVE-2025-8774?
A timing discrepancy vulnerability has been identified in the L1 Data Cache Handler component of riscv-boom SonicBOOM, affecting all versions up to 2.2.3. This flaw allows an attacker with local access to exploit observable discrepancies in timing, which may lead to unauthorized information exposure. The difficulty of executing this attack is high, and it requires a specific set of conditions to succeed. Despite early notifications of this vulnerability, the vendor has not issued a response or provided any remedial measures.
Affected Version(s)
SonicBOOM 2.2.0
SonicBOOM 2.2.1
SonicBOOM 2.2.2