Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-42807

Quick assessment

Affected
Bosch Sensortec COINES_SDK
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Bosch Sensortec COINES_SDK(版本 2.10 至 2.12.2)中 PC 桥接协议解码器存在一个基于堆的缓冲区溢出漏洞,攻击者可借此导致拒绝服务(进程崩溃),甚至可能实现任意代码执行。 桥接解码器({{bridge_decoder.c}})直接信任外部设备提供的数据包长度字段,并将其转发至主机响应队列({{mqueue_add_data}}),但未对目标缓冲区的边界进行校验。 一个恶意或被攻陷的 USB 或蓝牙低功耗(BLE)外设可以通告高达约 3 KB 的有效负载大小,超过了默认队列槽大小

CVSS 8.0 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-42807

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A heap-based buffer overflow vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK (versions 2.10 through 2.12.2) allows attackers to cause a denial of service (process crash) or potentially execute arbitrary code. The bridge decoder ({{bridge_decoder.c}}) trusts the packet length field provided by the external device and forwards it to the host response queue ({{mqueue_add_data}}) without validating the bounds of the destination buffer. A malicious or compromised USB or Bluetooth Low Energy (BLE) peripheral can advertise a payload size up to ~3 KB, which exceeds the default queue slot size of 255 bytes. This results in an unbounded heap overwrite ({{memcpy}}), corrupting adjacent heap metadata on the host system when processing the device's response.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Bosch Sensortec COINES_SDK 2.10 ~ 2.12.2 -

II. Public POCs for CVE-2026-42807

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-42807

登录查看更多情报信息。

Other References for CVE-2026-42807 (1)

Same Patch Batch · Bosch Sensortec · 2026-09-10 · 5 CVEs total

CVE-2026-42805 8.4 HIGH BHI385 SensorAPI 栈缓冲区溢出
CVE-2026-42804 7.6 HIGH CVE-2026-42804
CVE-2026-42808 6.8 MEDIUM Bosch COINES_SDK 2.0-2.11 流式读取缓冲区溢出
CVE-2026-42806 4.3 MEDIUM Bosch BME690 v1.0.3 越界读取漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-42807

No comments yet


Leave a comment