summaryrefslogtreecommitdiff
path: root/drivers/bluetooth
diff options
context:
space:
mode:
authorLuiz Augusto von Dentz <luiz.von.dentz@intel.com>2026-09-21 09:58:35 -0400
committerLuiz Augusto von Dentz <luiz.von.dentz@intel.com>2026-09-21 09:58:35 -0400
commitf7721562cb4d359413ac8b9a70ed4d7908b68915 (patch)
tree928cbf1c7c32685e3a57f5da2ff282dacf10a4e2 /drivers/bluetooth
parent019debf20bfd648b40ba10377ee0168db5eb241e (diff)
parent6d91041bb38b97e2feb625123cc0529d7b83a0e1 (diff)
downloadlinux-next-f7721562cb4d359413ac8b9a70ed4d7908b68915.tar.gz
linux-next-f7721562cb4d359413ac8b9a70ed4d7908b68915.zip
Merge branch 'bluetooth' into bluetooth-next
Diffstat (limited to 'drivers/bluetooth')
-rw-r--r--drivers/bluetooth/btintel_pcie.c16
1 files changed, 16 insertions, 0 deletions
diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
index 4807361a58a7..444cc50174fb 100644
--- a/drivers/bluetooth/btintel_pcie.c
+++ b/drivers/bluetooth/btintel_pcie.c
@@ -2065,6 +2065,11 @@ static void btintel_pcie_msix_tx_handle(struct btintel_pcie_data *data)
txq = &data->txq;
+ if (cr_hia >= txq->count) {
+ bt_dev_err(data->hdev, "TXQ: invalid cr_hia %u", cr_hia);
+ return;
+ }
+
while (cr_tia != cr_hia) {
data->tx_wait_done = true;
wake_up(&data->tx_wait_q);
@@ -2644,6 +2649,11 @@ static void btintel_pcie_msix_rx_handle(struct btintel_pcie_data *data)
rxq = &data->rxq;
+ if (cr_hia >= rxq->count) {
+ bt_dev_err(hdev, "RXQ: invalid cr_hia %u", cr_hia);
+ return;
+ }
+
/* The firmware sends multiple CD in a single MSI-X and it needs to
* process all received CDs in this interrupt.
*/
@@ -2651,6 +2661,12 @@ static void btintel_pcie_msix_rx_handle(struct btintel_pcie_data *data)
urbd1 = &rxq->urbd1s[cr_tia];
ipc_print_urbd1(data->hdev, urbd1, cr_tia);
+ if (urbd1->frbd_tag >= rxq->count) {
+ bt_dev_err(hdev, "RXQ: invalid frbd_tag %u",
+ urbd1->frbd_tag);
+ return;
+ }
+
buf = &rxq->bufs[urbd1->frbd_tag];
if (!buf) {
bt_dev_err(hdev, "RXQ: failed to get the DMA buffer for %d",