PT-2026-89334 · Bosch Sensortec · Coines Sdk
CVE-2026-42807
·
Published
2026-09-10
·
Updated
2026-09-10
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code.
The bridge decoder ({{bridge decoder.c}}) trusts the packet length field provided by the external device and forwards it to the host response queue ({{mqueue add data}}) without validating the bounds of the destination buffer.
A malicious or compromised USB or Bluetooth Low Energy (BLE) peripheral can advertise a payload size up to ~3 KB, which exceeds the default queue slot size of 255 bytes.
This results in an unbounded heap overwrite ({{memcpy}}), corrupting adjacent heap metadata on the host system when processing the device's response.
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coines Sdk