In rwt4tsmdetectndef of rw_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure due to a limited change in behavior based on the out of bounds data with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"217146741193074593608098226669961182961",
"17138486179906415212582624112398170197",
"186601714833488990582245702657038269122",
"257556729313138569156678361664852236343",
"213814533085605369366542942877938794952",
"80723568572663696951921903732011117876",
"326851065177076493979315239481818382670",
"171216877515348281457675203316091752066"
]
},
"id": "ASB-A-191444150-5e4e61b6",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/nfc/+/00e61a978be77d07c94175bbb6ebb4b78ac6526a",
"target": {
"file": "src/nfc/tags/rw_t4t.cc"
}
},
{
"digest": {
"length": 9087.0,
"function_hash": "212737049385358938029041550558306698657"
},
"id": "ASB-A-191444150-c51dcbf7",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/nfc/+/00e61a978be77d07c94175bbb6ebb4b78ac6526a",
"target": {
"function": "rw_t4t_sm_detect_ndef",
"file": "src/nfc/tags/rw_t4t.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/nfc/+/00e61a978be77d07c94175bbb6ebb4b78ac6526a"
],
"types": [
"ID"
],
"spl": "2021-11-01",
"severity": "High"
}