A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.
History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Silicon Labs
Silicon Labs silicon Labs Matter Github
Vendors & Products Silicon Labs
Silicon Labs silicon Labs Matter Github

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.
Title Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path
Weaknesses CWE-336
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Silabs

Published: 2026-07-23T21:05:22.113Z

Updated: 2026-07-24T13:40:36.220Z

Reserved: 2026-04-23T17:11:02.116Z

Link: CVE-2026-6924

cve-icon Vulnrichment

Updated: 2026-07-24T13:40:29.288Z

cve-icon NVD

No data.

cve-icon Redhat

No data.