Stack-Based Buffer Overflow in Bosch Sensortec BHI385 SensorAPI
CVE-2026-42805

8.4HIGH

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-42805?

A stack-based buffer overflow vulnerability exists in the Bosch Sensortec BHI385 SensorAPI within the debug message parser function. This vulnerability arises when the function fails to enforce bounds checks during the parsing of FIFO events, allowing an attacker to provide an oversized length byte from the event payload. As a result, excessive data can be copied into a fixed-size stack buffer, leading to potential memory corruption. This flaw poses significant risks, including firmware crashes, denial of service, or the execution of arbitrary code through adjacent stack data corruption when exploited by a malicious sensor or bus participant.

Affected Version(s)

BHI385 SensorAPI (C Library) 1.1.0 <= 2.1.0

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.