CVE-2026-6924 Details
Description
A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.
A vulnerability exists in the Silicon Labs SiWx917 Wi-Fi System-on-Chip due to improper entropy initialization, leading to the Deterministic Random Bit Generator (DRBG) using a predictable seed. Consequently, all random numbers generated within the Matter framework follow the same sequence, undermining randomness and potentially allowing for predictable outcomes in applications relying on this randomness. This issue was identified in a deprecated repository version 2.3.1-1.3.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-336 | Same Seed in Pseudo-Random Number Generator (PRNG) | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 23, 2026 | New CVE Received | [email protected] |