Stack-Based Buffer Overflow in Bosch Sensortec BHI360 SensorAPI
CVE-2026-42804
7.6HIGH
Key Information:
- Vendor
Bosch Sensortec
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-42804?
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI360 SensorAPI, specifically within the FIFO parsing and debug logging subsystem. It can be exploited by a physically positioned attacker who injects a malicious debug frame with an oversized message length. This causes a buffer overflow in a fixed-size stack buffer, allowing the attacker to corrupt adjacent stack data, including the return address. Due to the vulnerability's nature, an attacker can execute arbitrary code on the host microcontroller or cause a system crash.
Affected Version(s)
BHI360_SensorAPI (C-Library) 2.1.0 <= 2.2.0
