Out-of-Bounds Read Vulnerability in Bosch BME690 SensorAPI Driver
CVE-2026-42806

4.3MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-42806?

An out-of-bounds read vulnerability exists in the Bosch BME690 SensorAPI driver, specifically in the read_all_field_data function. This issue arises due to improper validation of the gas index extracted from sensor field data, allowing an attacker or compromised peripheral to manipulate the gas index value. When values exceed the valid range, it leads to potential memory access violations, resulting in measurement corruption or sensitive data leaks during telemetric logging.

Affected Version(s)

BME690 SensorAPI (C) 1.0.1 <= 1.0.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.