In phNxpNciHalprintres_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/hardware/nxp/nfc/+/491a4f0f42f1a922e0096df592ea4e19f1dfb24f",
"signature_version": "v1",
"deprecated": false,
"id": "PUB-A-169258733-a221365b",
"target": {
"function": "phNxpNciHal_print_res_status",
"file": "halimpl/hal/phNxpNciHal.cc"
},
"signature_type": "Function",
"digest": {
"length": 1843.0,
"function_hash": "145899811643926726504841734127427203008"
}
},
{
"source": "https://android.googlesource.com/platform/hardware/nxp/nfc/+/491a4f0f42f1a922e0096df592ea4e19f1dfb24f",
"signature_version": "v1",
"deprecated": false,
"id": "PUB-A-169258733-c1664c84",
"target": {
"file": "halimpl/hal/phNxpNciHal.cc"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"186546649332595719760709967096220487122",
"276028843360022147028961953549648120767",
"3958563350645446514168737349641104704",
"16342225463242291491226269122076074642",
"328374640030903947394618088068986507424",
"124409135069973804548425575301613334775",
"240771331944478748917531059421592021275",
"113714460987669737769620916473529989177",
"253859249321806032581105689844917368384",
"273986881014520327244882059344370763798",
"306981536673503638525659796381680761795",
"165192048633730649762790374355893509999",
"237079044174739157119155643684671891257",
"43779054585709293988804823572701059293",
"81010849652033626298022046608117070624",
"312844301519515496988965759614666486132",
"27529100634285236431217361127093045996",
"307587466860720780286910192283717646597",
"140672343804490970650717429586128574318",
"144190714571291946187433173811701333324"
]
}
}
],
"fixes": [
"https://android.googlesource.com/platform/hardware/nxp/nfc/+/491a4f0f42f1a922e0096df592ea4e19f1dfb24f"
],
"types": [
"EoP"
],
"severity": "Moderate",
"spl": "2021-06-01"
}