[PATCH] Bluetooth: btintel_pcie: fix TX descriptor bounds check

From: Ravindra

Date: Mon Sep 28 2026 - 01:44:24 EST


btintel_pcie_prepare_tx() uses tfd_index to access the TFD and data
buffer arrays before the index is advanced modulo txq->count. An index
equal to txq->count is one past the end of both arrays, so reject it in
the bounds check.

Signed-off-by: Ravindra <ravindra@xxxxxxxxx>
---
drivers/bluetooth/btintel_pcie.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_pcie.c
index 59cf600014bb..aaf409a9afb1 100644
--- a/drivers/bluetooth/btintel_pcie.c
+++ b/drivers/bluetooth/btintel_pcie.c
@@ -536,7 +536,7 @@ static int btintel_pcie_send_sync(struct btintel_pcie_data *data,

tfd_index = data->ia.tr_hia[BTINTEL_PCIE_TXQ_NUM];

- if (tfd_index > txq->count)
+ if (tfd_index >= txq->count)
return -ERANGE;

if (skb->len > BTINTEL_PCIE_BUFFER_SIZE - BTINTEL_PCIE_HCI_TYPE_LEN) {
--
2.43.0