CVE-2026-6924: Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path
A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6924?
CVE-2026-6924 has a high severity rating of 8.7 according to the CVSS score.
What does CVE-2026-6924 affect?
CVE-2026-6924 affects the entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt, leading to predictable random number generation.
What are the potential consequences of CVE-2026-6924?
Exploitation of CVE-2026-6924 can result in the generation of predictable random values, undermining cryptographic security.
How do I fix CVE-2026-6924?
To mitigate CVE-2026-6924, update to the latest version of Silicon Labs Matter SiWx917 TinyCrypt that addresses the entropy initialization issue.
When was CVE-2026-6924 published?
CVE-2026-6924 was published on July 23, 2026.