Stack-Based Buffer Overflow in Bosch Sensortec BHI385 SensorAPI
CVE-2026-42805
8.4HIGH
Key Information:
- Vendor
Bosch Sensortec
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-42805?
A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI within the debug message parser function. This vulnerability arises when the function fails to enforce bounds checks during the parsing of FIFO events, allowing an attacker to provide an oversized length byte from the event payload. As a result, excessive data can be copied into a fixed-size stack buffer, leading to potential memory corruption. This flaw poses significant risks, including firmware crashes, denial of service, or the execution of arbitrary code through adjacent stack data corruption when exploited by a malicious sensor or bus participant.
Affected Version(s)
BHI385 SensorAPI (C Library) 1.1.0 <= 2.1.0
