CVE-2022-20516
published 2022-12-16CVE-2022-20516: In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.76%
51.0th percentile
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224002331
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | system_nfc | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 13.0 rw_t3t.cc rw_t3t_act_handle_check_ndef_rsp out-of-bounds (A-224002331 / EUVD-2022-25776)
vuldb·2026-04-20·CVSS 7.5
CVE-2022-20516 [HIGH] Google Android 13.0 rw_t3t.cc rw_t3t_act_handle_check_ndef_rsp out-of-bounds (A-224002331 / EUVD-2022-25776)
A vulnerability marked as problematic has been reported in Google Android 13.0. This issue affects the function rw_t3t_act_handle_check_ndef_rsp of the file rw_t3t.cc. This manipulation causes out-of-bounds read.
The identification of this vulnerability is CVE-2022-20516. It is possible to initiate the attack remotely. There is no exploit available.
Applying a patch is the recommended action to fix this issue.
GHSA
GHSA-6973-4pp3-gvj6: In rw_t3t_act_handle_check_ndef_rsp of rw_t3t
ghsa_unreviewed·2022-12-20
CVE-2022-20516 [HIGH] CWE-190 GHSA-6973-4pp3-gvj6: In rw_t3t_act_handle_check_ndef_rsp of rw_t3t
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-224002331
OSV
CVE-2022-20516: In rw_t3t_act_handle_check_ndef_rsp of rw_t3t
osv·2022-12-01
CVE-2022-20516 CVE-2022-20516: In rw_t3t_act_handle_check_ndef_rsp of rw_t3t
In rw_t3t_act_handle_check_ndef_rsp of rw_t3t.cc, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published