PT-2026-89334 · Bosch Sensortec · Coines Sdk

CVE-2026-42807

·

Published

2026-09-10

·

Updated

2026-09-10

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code.
The bridge decoder ({{bridge decoder.c}}) trusts the packet length field provided by the external device and forwards it to the host response queue ({{mqueue add data}}) without validating the bounds of the destination buffer.
A malicious or compromised USB or Bluetooth Low Energy (BLE) peripheral can advertise a payload size up to ~3 KB, which exceeds the default queue slot size of 255 bytes.
This results in an unbounded heap overwrite ({{memcpy}}), corrupting adjacent heap metadata on the host system when processing the device's response.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42807

Affected Products

Coines Sdk