diff options
| author | Luiz Augusto von Dentz <luiz.von.dentz@intel.com> | 2026-09-21 09:58:35 -0400 |
|---|---|---|
| committer | Luiz Augusto von Dentz <luiz.von.dentz@intel.com> | 2026-09-21 09:58:35 -0400 |
| commit | f7721562cb4d359413ac8b9a70ed4d7908b68915 (patch) | |
| tree | 928cbf1c7c32685e3a57f5da2ff282dacf10a4e2 /drivers/bluetooth | |
| parent | 019debf20bfd648b40ba10377ee0168db5eb241e (diff) | |
| parent | 6d91041bb38b97e2feb625123cc0529d7b83a0e1 (diff) | |
| download | linux-next-f7721562cb4d359413ac8b9a70ed4d7908b68915.tar.gz linux-next-f7721562cb4d359413ac8b9a70ed4d7908b68915.zip | |
Merge branch 'bluetooth' into bluetooth-next
Diffstat (limited to 'drivers/bluetooth')
| -rw-r--r-- | drivers/bluetooth/btintel_pcie.c | 16 |
1 files changed, 16 insertions, 0 deletions
diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c index 4807361a58a7..444cc50174fb 100644 --- a/drivers/bluetooth/btintel_pcie.c +++ b/drivers/bluetooth/btintel_pcie.c @@ -2065,6 +2065,11 @@ static void btintel_pcie_msix_tx_handle(struct btintel_pcie_data *data) txq = &data->txq; + if (cr_hia >= txq->count) { + bt_dev_err(data->hdev, "TXQ: invalid cr_hia %u", cr_hia); + return; + } + while (cr_tia != cr_hia) { data->tx_wait_done = true; wake_up(&data->tx_wait_q); @@ -2644,6 +2649,11 @@ static void btintel_pcie_msix_rx_handle(struct btintel_pcie_data *data) rxq = &data->rxq; + if (cr_hia >= rxq->count) { + bt_dev_err(hdev, "RXQ: invalid cr_hia %u", cr_hia); + return; + } + /* The firmware sends multiple CD in a single MSI-X and it needs to * process all received CDs in this interrupt. */ @@ -2651,6 +2661,12 @@ static void btintel_pcie_msix_rx_handle(struct btintel_pcie_data *data) urbd1 = &rxq->urbd1s[cr_tia]; ipc_print_urbd1(data->hdev, urbd1, cr_tia); + if (urbd1->frbd_tag >= rxq->count) { + bt_dev_err(hdev, "RXQ: invalid frbd_tag %u", + urbd1->frbd_tag); + return; + } + buf = &rxq->bufs[urbd1->frbd_tag]; if (!buf) { bt_dev_err(hdev, "RXQ: failed to get the DMA buffer for %d", |
