CVE-2026-55286
platform/hardware/st/nfc: Improper Restriction of Operations within the Bounds of a Memory Buffer (CVE-2026-55286)
Description
In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected operating systems
mobile
google / android17.0
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
1717:017-next17-next:0Metrics
Show all metrics
Weakness classes (CWE)
CWE-119Class
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-10-07 14:22 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:o:google:android:17.0:-:*:*:*:*:*:*
- Reference Type: Android (associated with Google Inc. or Open Handset Alliance): https://source.android.com/docs/security/bulletin/2026/2026-10-01 Types: Patch, Vendor Advisory
- CVE Modified2026-10-06 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-55286","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- SSVC: {"id":"CVE-2026-55286","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-10-05 20:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-119
- SSVC: {"id":"CVE-2026-55286","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-10-05 19:17 UTC· security@android.com
- Description: In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/55xxx/CVE-2026-55286.json">CVE-2026-55286</a>
- Reference: https://source.android.com/docs/security/bulletin/2026/2026-10-01