PT-2026-89335 · Bosch Sensortec · Coines Sdk
CVE-2026-42808
·
Published
2026-09-10
·
Updated
2026-09-10
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
An issue was discovered in Bosch Sensortec COINES SDK versions 2.0 through 2.11.
The host streaming API function {{coines read stream sensor data()}} fails to validate the boundaries of the caller-provided destination buffer.
Internally, the stream processing mechanism in {{comm intf process stream response()}} discards the requested {{number of samples}} argument and copies the entirety of the streaming ring buffer's accumulated data into {{coines stream rsp buf}}.
Subsequently, {{coines read stream sensor data()}} unconditionally executes a {{memcpy}} of the ring buffer size into the caller-provided buffer without verifying if the destination memory allocation is large enough.
A malicious or compromised hardware board connected via USB or BLE can exploit this by streaming a high volume of sensor samples, causing a heap or stack-based buffer overflow on the host desktop environment.
This can result in a Denial of Service (DoS) or potential arbitrary code execution on the host machine.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coines Sdk