VYPR
Unrated severityNVD Advisory· Published Jul 7, 2026· Updated Jul 7, 2026

Insufficient Entropy in Raspberry Pi 5 and Compute Module 5

CVE-2026-13199

Description

EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and devices, potentially making it easier to exploit other vulnerabilities. Additionally, the low-quality RNG seed may affect the quality of random numbers or delay booting while sufficient entropy is accumulated from other sources.

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.