CVE-2026-13199: Raspberry Pi 5 And Compute Module 5

Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.

EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across boots and devices, potentially making it easier to exploit other vulnerabilities. Additionally, the low-quality RNG seed may affect the quality of random numbers or delay booting while sufficient entropy is accumulated from other sources.

Affected products

  • Raspberry Pi Raspberry Pi 5 And Compute Module 5: before 28.22-1 (fixed in 28.22-1)

Published 2026-07-07. Last modified 2026-07-07.