CVE-2026-6924 PUBLISHED

Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path

Assigner: Silabs
Reserved: 23.04.2026 Published: 23.07.2026 Updated: 24.07.2026

A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Silicon Labs
Product Silicon Labs Matter Github
Versions Default: unaffected
  • Version 0 is affected

Credits

  • Junming C. (@Chapoly1305) and Prof. Qiang Zeng of George Mason University reporter

References

Problem Types

  • CWE-336: Same Seed in Pseudo-Random Number Generator (PRNG) CWE

Impacts

  • CAPEC-97: Cryptanalysis