EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and devices, potentially making it easier to exploit other vulnerabilities. Additionally, the low-quality RNG seed may affect the quality of random numbers or delay booting while sufficient entropy is accumulated from other sources.
References
Configurations
No configuration.
History
07 Jul 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.0 |
07 Jul 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-07 09:16
Updated : 2026-07-07 14:16
NVD link : CVE-2026-13199
Mitre link : CVE-2026-13199
CVE.ORG link : CVE-2026-13199
JSON object : View
Products Affected
No product.
CWE
CWE-331
Insufficient Entropy
