Out-of-Bounds Read Vulnerability in Bosch BME690 SensorAPI Driver
CVE-2026-42806
4.3MEDIUM
Key Information:
- Vendor
Bosch Sensortec
- Status
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-42806?
An out-of-bounds read vulnerability exists in the Bosch BME690 SensorAPI driver, specifically in the read_all_field_data function. This issue arises due to improper validation of the gas index extracted from sensor field data, allowing an attacker or compromised peripheral to manipulate the gas index value. When values exceed the valid range, it leads to potential memory access violations, resulting in measurement corruption or sensitive data leaks during telemetric logging.
Affected Version(s)
BME690 SensorAPI (C) 1.0.1 <= 1.0.3
