The CISPA team in Saarbrücken (Germany) discovered a number of significant security vulnerabilities in T-Head C906/906/910 CPU cores.
More details at https://www.theregister.com/2024/08/07/riscv_business_thead_...
More details at https://www.theregister.com/2024/08/07/riscv_business_thead_...
When I wanted to benchmark their implementation last year I patched a kernel to enable it, and needed to consult the open source part of the core [0] to figure out that they placed the enable CSR bit in a different location than the final ratified spec. [1]
[0] https://github.com/T-head-Semi/openc906 (doesn't include XTheadVector extension)
> No, software updates or patches cannot fix this vulnerability because it is a hardware bug. The only mitigation is to disable the vector extension in the CPU, which unfortunately impacts the CPU’s performance.