What is CVE-2026-6924?
A vulnerability in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed, leading to all random numbers in Matter code using the same stream. This allows attackers to predict critical cryptographic values. No patch is expected as the affected repository was already deprecated when the flaw was discovered.
Azərbaycanca: CVE-2026-6924, SiWx917 çipində entropiya inisializasiya xətası səbəbindən DRBG proqnozlaşdırıla bilən bir başlanğıc dəyərdən istifadə edir. Bu, Matter kodunda yaradılan bütün təsadüfi ədədlərin eyni olduğu mənasına gəlir. Zərərçəkənlər bu zəiflikdən istifadə edərək şifrələmə açarı kimi kritik təsadüfi ədədləri təxmin edə bilər.
FAQ2
Why does CVE-2026-6924 allow random numbers to be predictable in the SiWx917 chip?
The vulnerability occurs because an entropy initialization flaw causes the DRBG to use a predictable seed.
Is a patch available for CVE-2026-6924?
No patch is expected because the affected repository was already deprecated when the flaw was discovered.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.