Skip to main content
Disclosures

Bosch Sensortec · BHI385 SensorAPI

BHI385 Debug FIFO Stack Buffer Overflow

8.4high
SecMateSECMATE-2026-0033
VendorBosch Sensortec
ProductBHI385 SensorAPI
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Advisories
Timeline
Reported
Nov 11, 2025
Published
Aug 31, 2026
Summary

BHI385 SensorAPI versions from 1.1.0 to before 2.1.0 read a message length from a sensor FIFO event and copy that many bytes into a fixed 17-byte stack buffer in bhi385_parse_debug_message() without enforcing the buffer limit. A malicious sensor or bus participant can corrupt adjacent stack data, crash the host, or potentially execute arbitrary code.

What's hidden in yours?

Find out