Fix integer underflow in rw_ci_data_cback This commit addresses an out-of-bounds read vulnerability in the rw_ci_data_cback function caused by an integer underflow when handling zero-length payloads in RW_CI_STATE_UID and RW_CI_STATE_ATTRIB states. By validating the length of the response before decrementing it, we ensure the pointer does not go out of bounds. Bug: 503550880 Test: atest libnfc-nci-tests:RwCiTest Flag: EXEMPT BUGFIX (cherry picked from commit d61d8a670948bfc392e748e07c0542b7b4d372ea) Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:e23770dba32e92ac7a8c6d372354fffd845d6df2 Merged-In: I500f5e8b37376a233e95edc4471766f095cc1786 Change-Id: I500f5e8b37376a233e95edc4471766f095cc1786