CVE-2026-6924

Summary

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.

Affected Software

VendorProductVersion RangeStatus
Silicon LabsSilicon Labs Matter Github0affected

Weaknesses

  • CWE-336: CWE-336: Same Seed in Pseudo-Random Number Generator (PRNG)

References