Vulnerability Description
EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and devices, potentially making it easier to exploit other vulnerabilities. Additionally, the low-quality RNG seed may affect the quality of random numbers or delay booting while sufficient entropy is accumulated from other sources.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/raspberrypi/rpi-eeprom/pull/841
- https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2026-13199
FAQ
What is CVE-2026-13199?
CVE-2026-13199 is a vulnerability with a CVSS score of 4.0 (MEDIUM). EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and devices, potentially making ...
How severe is CVE-2026-13199?
CVE-2026-13199 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-13199?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.