Fix integer underflow in rw_ci_data_cback

This commit addresses an out-of-bounds read vulnerability in the
rw_ci_data_cback function caused by an integer underflow when handling
zero-length payloads in RW_CI_STATE_UID and RW_CI_STATE_ATTRIB states.
By validating the length of the response before decrementing it, we
ensure the pointer does not go out of bounds.

Bug: 503550880
Test: atest libnfc-nci-tests:RwCiTest
Flag: EXEMPT BUGFIX

(cherry picked from commit d61d8a670948bfc392e748e07c0542b7b4d372ea)
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:e23770dba32e92ac7a8c6d372354fffd845d6df2
Merged-In: I500f5e8b37376a233e95edc4471766f095cc1786
Change-Id: I500f5e8b37376a233e95edc4471766f095cc1786
2 files changed