In rwi93sendtolower of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"236478541848971608367355579749868908016",
"297506873988724218212587653623286873316",
"137332190083755097512770976647837848568",
"234852275915054898835103494819916860185",
"230157257563720888555979030667711721965",
"56094799140808690291712126572038728735",
"314468345784876594877429514339984928327"
]
},
"id": "PUB-A-157650357-48ac4561",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/system/nfc/+/14331cf338d9078ecdd5c1aeb7c9d44b705e0144",
"target": {
"file": "src/nfc/tags/rw_i93.cc"
}
},
{
"digest": {
"length": 664.0,
"function_hash": "62212644360992255378997079556720221144"
},
"id": "PUB-A-157650357-4c6c6ce3",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/system/nfc/+/14331cf338d9078ecdd5c1aeb7c9d44b705e0144",
"target": {
"function": "rw_i93_send_to_lower",
"file": "src/nfc/tags/rw_i93.cc"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/system/nfc/+/14331cf338d9078ecdd5c1aeb7c9d44b705e0144"
],
"types": [
"EoP"
],
"spl": "2021-06-01",
"severity": "Moderate"
}