RE: [PATCH] Bluetooth: btintel_pcie: fix TX descriptor bounds check

From: Ravindra

Date: Mon Sep 28 2026 - 02:01:54 EST


Cc: chethan.tumkur.narayan@xxxxxxxxx, kiran.k@xxxxxxxxx

Adding Kiran and Chethan to the thread for visibility. The patch was sent
earlier; no resend is needed.

> Subject: [PATCH] Bluetooth: btintel_pcie: fix TX descriptor bounds check
>
> btintel_pcie_prepare_tx() uses tfd_index to access the TFD and data buffer
> arrays before the index is advanced modulo txq->count. An index equal to
> txq->count is one past the end of both arrays, so reject it in the bounds check.
>
> Signed-off-by: Ravindra <ravindra@xxxxxxxxx>
> ---
> drivers/bluetooth/btintel_pcie.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
> index 59cf600014bb..aaf409a9afb1 100644
> --- a/drivers/bluetooth/btintel_pcie.c
> +++ b/drivers/bluetooth/btintel_pcie.c
> @@ -536,7 +536,7 @@ static int btintel_pcie_send_sync(struct
> btintel_pcie_data *data,
>
> tfd_index = data->ia.tr_hia[BTINTEL_PCIE_TXQ_NUM];
>
> - if (tfd_index > txq->count)
> + if (tfd_index >= txq->count)
> return -ERANGE;
>
> if (skb->len > BTINTEL_PCIE_BUFFER_SIZE -
> BTINTEL_PCIE_HCI_TYPE_LEN) {
> --
> 2.43.0