{"id":"PUB-A-238083126","details":"In phNxpNciHal_ioctl of phNxpNciHal.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.","aliases":["A-238083126","CVE-2022-20541"],"modified":"2026-05-29T15:55:33.750044621Z","published":"2022-12-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2022-12-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/hardware/nxp/nfc/+/567c0496a8e80e96c15c02cb8f063e65008943cd"}],"affected":[{"package":{"name":"platform/hardware/nxp/nfc","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2022-12-01"}]}],"versions":["13"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/hardware/nxp/nfc/+/567c0496a8e80e96c15c02cb8f063e65008943cd"],"spl":"2022-12-01","vanir_signatures":[{"signature_version":"v1","id":"PUB-A-238083126-01fa3771","source":"https://android.googlesource.com/platform/hardware/nxp/nfc/+/567c0496a8e80e96c15c02cb8f063e65008943cd","digest":{"threshold":0.9,"line_hashes":["77204802751211500839040285979978555725","300919541896282715494546212023969125797","5360319990706156878907516925622561494","114586680526472280958446184655492075570"]},"signature_type":"Line","deprecated":false,"match_only_versions":["13"],"target":{"file":"pn8x/halimpl/hal/phNxpNciHal.cc"}},{"signature_version":"v1","id":"PUB-A-238083126-23791c7d","deprecated":false,"digest":{"function_hash":"72885685740246479488067452998063208502","length":3237},"source":"https://android.googlesource.com/platform/hardware/nxp/nfc/+/567c0496a8e80e96c15c02cb8f063e65008943cd","signature_type":"Function","match_only_versions":["13"],"target":{"file":"pn8x/halimpl/hal/phNxpNciHal.cc","function":"phNxpNciHal_ioctl"}}],"severity":"Moderate","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-238083126.json"}}],"schema_version":"1.7.5"}