a function called 'nlaparse', do not check the len of para, it will check nlatype (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.
{ "severity": "High", "types": [ "EoP" ], "spl": "2022-09-05" }
"https://storage.googleapis.com/android-osv/ASB-A-238379819.json"