CVE-2026-13199

EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and devices, potentially making it easier to exploit other vulnerabilities. Additionally, the low-quality RNG seed may affect the quality of random numbers or delay booting while sufficient entropy is accumulated from other sources.
Configurations

No configuration.

History

07 Jul 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.0

07 Jul 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-07 09:16

Updated : 2026-07-07 14:16


NVD link : CVE-2026-13199

Mitre link : CVE-2026-13199

CVE.ORG link : CVE-2026-13199


JSON object : View

Products Affected

No product.

CWE
CWE-331

Insufficient Entropy