Fix OOB write in rw_mfc_handle_read_op

Buganizer issue b/503557185 reports a heap buffer overflow vulnerability in com.android.nfc during Mifare Classic NDEF reads.

This CL adds a rollback mechanism that snapshots the ndef_length and
ndef_start_pos before TLV decoding. It validates the new length and
restores the original values if inflation is detected. Control flow is also updated to prevent further block reads upon failure.

Bug: 503557185
Bug: 503553866
Test: manual
Flag: EXEMPT BUGFIX
(cherry picked from commit 50df1ba6f310a3947ff257d5fee24bb2b371af0c)
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:0903c609fb0e36312e6b25447b6643fb8d79edb7
Merged-In: I2e26dfa48e96c5fee4bbff14c0b0b7be81d19213
Change-Id: I2e26dfa48e96c5fee4bbff14c0b0b7be81d19213
1 file changed