In phNxpNciHalprocessextrsp of phNxpNciHalext.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
{ "severity": "Moderate", "fixes": [ "https://android.googlesource.com/platform/hardware/nxp/nfc/+/fc44434f7728cdf6cd6e29729dfdb79d2f1809e4" ], "vanir_signatures": [ { "source": "https://android.googlesource.com/platform/hardware/nxp/nfc/+/fc44434f7728cdf6cd6e29729dfdb79d2f1809e4", "id": "PUB-A-169258743-be804e2e", "digest": { "function_hash": "144957320661705057696024866343318128348", "length": 7773.0 }, "signature_type": "Function", "deprecated": false, "target": { "function": "phNxpNciHal_process_ext_rsp", "file": "halimpl/hal/phNxpNciHal_ext.cc" }, "signature_version": "v1" }, { "source": "https://android.googlesource.com/platform/hardware/nxp/nfc/+/fc44434f7728cdf6cd6e29729dfdb79d2f1809e4", "id": "PUB-A-169258743-cdf3fa2f", "digest": { "threshold": 0.9, "line_hashes": [ "110608516626049271395258159091629464579", "199172325690527993752378671901326361324", "19184127120336552583878525553097528016", "178353908166092922115802535596088121917" ] }, "signature_type": "Line", "deprecated": false, "target": { "file": "halimpl/hal/phNxpNciHal_ext.cc" }, "signature_version": "v1" } ], "spl": "2021-06-01", "types": [ "EoP" ] }