PT-2026-56167 · Raspberry Pi · Raspberry Pi 5+1
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Raspberry Pi 5 (affected versions not specified)
Compute Module 5 (affected versions not specified)
Description
EEPROM firmware produces non-random KASLR (Kernel Address Space Layout Randomization, a security technique that randomizes the memory addresses used by the kernel) and RNG (Random Number Generator) seed values. This leads to consistent kernel addresses across different boots and devices, which may facilitate the exploitation of other issues. Furthermore, the low-quality RNG seed can degrade the quality of random numbers or cause boot delays while the system waits to accumulate sufficient entropy from other sources.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Compute Module 5
Raspberry Pi 5