In phNxpNciHalprintres_status of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 1843.0, "function_hash": "145899811643926726504841734127427203008" }, "id": "PUB-A-169258733-a221365b", "source": "https://android.googlesource.com/platform/hardware/nxp/nfc/+/491a4f0f42f1a922e0096df592ea4e19f1dfb24f", "deprecated": false, "signature_version": "v1", "target": { "file": "halimpl/hal/phNxpNciHal.cc", "function": "phNxpNciHal_print_res_status" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "186546649332595719760709967096220487122", "276028843360022147028961953549648120767", "3958563350645446514168737349641104704", "16342225463242291491226269122076074642", "328374640030903947394618088068986507424", "124409135069973804548425575301613334775", "240771331944478748917531059421592021275", "113714460987669737769620916473529989177", "253859249321806032581105689844917368384", "273986881014520327244882059344370763798", "306981536673503638525659796381680761795", "165192048633730649762790374355893509999", "237079044174739157119155643684671891257", "43779054585709293988804823572701059293", "81010849652033626298022046608117070624", "312844301519515496988965759614666486132", "27529100634285236431217361127093045996", "307587466860720780286910192283717646597", "140672343804490970650717429586128574318", "144190714571291946187433173811701333324" ] }, "id": "PUB-A-169258733-c1664c84", "source": "https://android.googlesource.com/platform/hardware/nxp/nfc/+/491a4f0f42f1a922e0096df592ea4e19f1dfb24f", "deprecated": false, "signature_version": "v1", "target": { "file": "halimpl/hal/phNxpNciHal.cc" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/hardware/nxp/nfc/+/491a4f0f42f1a922e0096df592ea4e19f1dfb24f" ], "spl": "2021-06-01", "severity": "Moderate", "types": [ "EoP" ] }