From nobody Mon Sep 28 16:22:44 2026 Received: from smtpbgjp3.qq.com (smtpbgjp3.qq.com [54.92.39.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BF9943E49C7; Thu, 20 Aug 2026 09:19:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=54.92.39.34 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787217564; cv=none; b=Qtpq4k+4sV8T58/uBVSx9Ri6OzNlTvqGheDMPf8upkeJb/Uvu2/7EI49sgOnozXW5VnQcNn1Zi8jCe4pH/qVMNGR0DNHajmgdJDzJ4lnnmUhQzLUVTUpDqBJNse8TQB/xP8HlQCIlgLXdwLvA6b4D0dfEHirzYkZeebz/bQaRfA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787217564; c=relaxed/simple; bh=mbW2BIMMfVGSsldSCbqG5lvosCYbDbmQRjQmZXfih54=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=DgiitC9Dgy204gLaMQM6J61W0Er+GbA4RrOEJnUIiJwazQqM09X8+qVy46T4vHIFzeJQQPPdV9L8gXU1+aetu8/X+WO95HsVtd3ABWkBrTa4v97T+nLisddqi/a1cIPSOZELDIs2KAi1qoOn1dsDq1UAwRLtt0DbeVW2K4MJGc8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uniontech.com; spf=pass smtp.mailfrom=uniontech.com; dkim=pass (1024-bit key) header.d=uniontech.com header.i=@uniontech.com header.b=VF3x00Za; arc=none smtp.client-ip=54.92.39.34 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uniontech.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=uniontech.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=uniontech.com header.i=@uniontech.com header.b="VF3x00Za" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=uniontech.com; s=onoh2408; t=1787217526; bh=3zpUkUlVsO35ZlDot63p91o0zUDXl0jQpg3ZCLVGlI8=; h=From:Date:Subject:MIME-Version:Message-Id:To; b=VF3x00ZaSVgKTskAXh6MWQKuP0Ff4/3Y/XoQF0RVUoqfHNuuJSaNqbfogz+zitoas AYqVcafu6nsBTuSiggT3c6BI0OSzJKIpy77JvV1ZcFl774qD1xjR7jDeQpdBun68l7 /qwegoyLVbcRS2BOTtKy8k54HpwzO7GYMGnxZLx8= X-QQ-mid: zesmtpgz4t1787217520t1d6ae224 X-QQ-Originating-IP: BAEvVQstqlpOZwMBF6qcoX2Opdj6hRo/Vjp7XeSXScQ= Received: from [10.10.7.64] ( [1.202.39.170]) by bizesmtp.qq.com (ESMTP) with id ; Thu, 20 Aug 2026 17:18:39 +0800 (CST) X-QQ-SSF: 0000000000000000000000000000000 X-QQ-GoodBg: 1 X-BIZMAIL-ID: 7165249167432056427 From: ZhaoJinming Date: Thu, 20 Aug 2026 17:17:38 +0800 Subject: [PATCH 1/3] Bluetooth: btintel_pcie: Fix off-by-one bounds checks in synchronous paths Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260820-btintel_pcie_bounds_fixes-v1-1-c9dcd1ac8bf6@uniontech.com> References: <20260820-btintel_pcie_bounds_fixes-v1-0-c9dcd1ac8bf6@uniontech.com> In-Reply-To: <20260820-btintel_pcie_bounds_fixes-v1-0-c9dcd1ac8bf6@uniontech.com> To: Luiz Augusto von Dentz , Marcel Holtmann , Paul Menzel Cc: linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org X-Mailer: b4 0.14.2 X-QQ-SENDSIZE: 520 Feedback-ID: zesmtpgz:uniontech.com:qybglogicsvrsz:qybglogicsvrsz4b-0 X-QQ-XMAILINFO: OCbhq8eaXCOaRGjSbYeD6ORsoIaYZ35rtU/emSJF5+KfHgxvZ2o4NiOE nsqHT5CAWyQT3NnWJ//bl15zrMTrnFvE3M6rrie/A0XlwP6RjpoNbNaypcBUtJu6AdZl5Ak +0IN6pYD3lfk4JtmQ72szwWlsKZwgGiUJuA7yXWDrA8nMHlXrFJoFu85AaQQBY5lJTjGm9G ThF0KOlS3ztTpJ1GePP4qJvAUjhtJKSQsCuX1FgI1FXFra7LVcmBF4rSrc3QSCgIuk2fFzs /nEB2YrNC0DM66FdKHFTaf7Wl/BMr01EzioGq13w3aqekVX8mrMznOgRztrrcGrXMsI8YZd 70kGMrwxMeirfT4We5PZDWILZDDNIG0EClJeIgxSmo7+igeGXsoMj513nvE9Ps0U6FL0OX6 SD8xVek/HKukvuMkacpxIfh6Rr1QVzJ5CDCDeW0+z0TkLnE9GxkKfc77BomtpVzQ+9OdBGa 4JU0gtsCC6rnsfqS76RBgJ6VfkeBlR0E/Gya0uhwawFaFcDrYgz6ogrQCFaWYrm389qZylF EISdQ8c8sxa8Ott+qTt+4JVfHNneXi5p+erPT9xKYal3fF8qVh1E5JGAgBWdsXQkkXxZ1kY JAUq8z5R8sQ8sPscTwv/9FoW1xPPUbT3nLunaptiuYLpAav9w0SuRgPIt3LAaP0OdR+OUxT 8loFvj8gDsy2KsgRSm+KElLj39J5T9djioMxmpEoO5nGxJfthuRCmIMqS4Ywrr/My8bCgyA uS2L3IRiPXsT41kbbq4+QeLhLOZoJTiQ+QWqeOZtJc8CsaRRkhglJAVDWHDV0P4EGBuL1Im 7krz6L8iRgN15NtHKPxiXh0D5o6rM1IUML9xKCRJPZ2ejrQE765ZNeteA+usWCQ2OuJJ30q 4Uk/vdqm4QGYf8Wmc23bwhQyvx+PhLS9+ghiNK1Oe3vxsrzFQ4R6kg7RFtutTjp7q+1xLzD WXaHmOghNXZSb7szcAfpFp49fHxTamMAHR+MEMmhBePzo4xQMJhz8bD2W5Wp+33Z6CEnQbe ArWvu42PutMJnvKz3LGB31Li9dK+R1e08H8qBUQQ== X-QQ-XMRINFO: OD9hHCdaPRBwH5bRRRw8tsiH4UAatJqXfg== X-QQ-RECHKSPAM: 0 Fix two off-by-one errors where '>' should have been '>=3D' when checking array indices against queue count: 1. btintel_pcie_send_sync(): tfd_index from tr_hia is used to index txq->tfds[] and txq->bufs[]. When tfd_index =3D=3D txq->count (32), btintel_pcie_prepare_tx() writes past the end of both arrays. 2. btintel_pcie_submit_rx(): frbd_index from tr_hia is used to index rxq->frbds[] and rxq->bufs[]. When frbd_index =3D=3D rxq->count (64), btintel_pcie_prepare_rx() writes past the end of both arrays. Fixes: c2b636b3f788 ("Bluetooth: btintel_pcie: Add support for PCIe transpo= rt") Signed-off-by: ZhaoJinming --- drivers/bluetooth/btintel_pcie.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_p= cie.c index 2b7231be5973d399f7f2fde344032b2f3e394365..fe50c5699e12ef3819577e0f0bd= 1b79d4340bd9e 100644 --- a/drivers/bluetooth/btintel_pcie.c +++ b/drivers/bluetooth/btintel_pcie.c @@ -401,7 +401,7 @@ static int btintel_pcie_send_sync(struct btintel_pcie_d= ata *data, =20 tfd_index =3D data->ia.tr_hia[BTINTEL_PCIE_TXQ_NUM]; =20 - if (tfd_index > txq->count) + if (tfd_index >=3D txq->count) return -ERANGE; =20 /* Firmware raises alive interrupt on HCI_OP_RESET or @@ -502,7 +502,7 @@ static int btintel_pcie_submit_rx(struct btintel_pcie_d= ata *data) =20 frbd_index =3D data->ia.tr_hia[BTINTEL_PCIE_RXQ_NUM]; =20 - if (frbd_index > rxq->count) + if (frbd_index >=3D rxq->count) return -ERANGE; =20 /* Prepare for RX submit. It updates the FRBD with the address of DMA --=20 2.51.0 From nobody Mon Sep 28 16:22:44 2026 Received: from smtpbg150.qq.com (smtpbg150.qq.com [18.132.163.193]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 409F73E3DB8; Thu, 20 Aug 2026 09:19:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=18.132.163.193 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787217572; cv=none; b=cMypjJjlOFRQBzToV8e4JY/712tbNY6BronjwxWa+H5Ic4Uh4wGOPTx9d7qcXzVOX2HIKiZbZ8M/EDlIQq6YJ0kPv0S6J+fTKIXUtbKQqBNMhkcE13tBhMKkYH61Sqr+b0YIP5gXRokVV10AilU6C9zZUq6xy4Cd/gDseDAg2iY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787217572; c=relaxed/simple; bh=wABNHtf/jhl+bCNfxQywUxmlPEEYiVZNUBWI1h1LDXc=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=dzND8nJRCrK5Ekf4bK++tsADgSt3AzSZU+evB/VNbskzIjkez1ctdHLY90hyeAiKGE4pdx12mYbS0+D9d63ejCcwpeZ4qWV9jzL8tLawzcrXX1jpeEkRr6/ZCz0KSRT02/Iujdwv2msGadvizHFbJMUn8ZZ92NnjJY5gPRLeQ7s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uniontech.com; spf=pass smtp.mailfrom=uniontech.com; dkim=pass (1024-bit key) header.d=uniontech.com header.i=@uniontech.com header.b=E58AmQHY; arc=none smtp.client-ip=18.132.163.193 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uniontech.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=uniontech.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=uniontech.com header.i=@uniontech.com header.b="E58AmQHY" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=uniontech.com; s=onoh2408; t=1787217529; bh=esuAdSeFMgBZzfHd91AAGsnCrEFkcP/WEbPLnlNUfJA=; h=From:Date:Subject:MIME-Version:Message-Id:To; b=E58AmQHYPvW+xuKbryDf+aMG2fMFgSnSgx7YRmNf3ZjGNwbRt59Wn7jKV39AunoMA VkG+OspGiH7BloLHNxFRMJG6NjKqitqlkC/Z7alA2UXYefrADRIjDji/VO0ov5eq/R Enr6gmwSPWqzgd5ridoslNd/bxzFF8NKqSnppD4Q= X-QQ-mid: zesmtpgz4t1787217524t79f4ffad X-QQ-Originating-IP: 8FtOVKAp088ggL563eHGGJT4HGNEB+CM8HTvtCnnIoE= Received: from [10.10.7.64] ( [1.202.39.170]) by bizesmtp.qq.com (ESMTP) with id ; Thu, 20 Aug 2026 17:18:43 +0800 (CST) X-QQ-SSF: 0000000000000000000000000000000 X-QQ-GoodBg: 1 X-BIZMAIL-ID: 4207000441139473809 From: ZhaoJinming Date: Thu, 20 Aug 2026 17:17:39 +0800 Subject: [PATCH 2/3] Bluetooth: btintel_pcie: Fix bounds checks in TX completion handler Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260820-btintel_pcie_bounds_fixes-v1-2-c9dcd1ac8bf6@uniontech.com> References: <20260820-btintel_pcie_bounds_fixes-v1-0-c9dcd1ac8bf6@uniontech.com> In-Reply-To: <20260820-btintel_pcie_bounds_fixes-v1-0-c9dcd1ac8bf6@uniontech.com> To: Luiz Augusto von Dentz , Marcel Holtmann , Paul Menzel Cc: linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org X-Mailer: b4 0.14.2 X-QQ-SENDSIZE: 520 Feedback-ID: zesmtpgz:uniontech.com:qybglogicsvrsz:qybglogicsvrsz4b-0 X-QQ-XMAILINFO: OWfylOJ3yY502n6RMmKVAeKagMtJudRQGOOSm6i08j1wC8+DkO/vu8iO Emt0kBc9vp0xGbCmvD1Mud4RoOoPMRhpoeP8xdk8Hn4jIiS7oNnTSqOA2jKaq7yWoDcsNux xK+eX9fh4h+BHrGsoyqqPUs6K7MOXSIlvbuunn/V8Mqv+c//9CZfiGzBqaLiPhZRT/11LwC enQCzP0i6pnbSJiJJrNK0ffetYLHh0+drl5mRyF2L9f3Qz9mHnCL1iBVd2SEgT1YO3Q4eUt Z/NZOWnOvYIjdg7pTLPCVxzsSy8LV6Hd8RXeyzTy3v2GIyFXvDbd2EfUpRfon9ty+vYVChk aWjLt7IILQVrzE+3P2CzugLNGbUidEwZ2bef8d+iFnG4ZUfuk7u5NtUOOCG3ljengN1GbAG Gn3je8N5xIlflr6KMLSjqm7POzd3HG8aBGz4P5TrIaaj4UKo/vcJJAoy0+XLki7BpxmaCTK S6G8Rv8gVJHQZ5PARuRwgFBXBh6wXGNAfPnjN4gc3YJpj9Rg49ktLyHxK8rJIkTbS42mnHX vgo3G7JVc9U9EVuWroPd9YXgWeCpHSSIlb1ADnO0rhUitTbt+evTj64XgVNsExk7vlme6yh doY6nNtucMfD6SnuZT2u4s5vcoD5earBRoKBUPB6xEQVcQLmsTWqj7gP+YI1Mm+njvNs9/U N8mQpxJ2UUtE0GJEkHgMOwGPsHJh/sc/aufeE0lfUtqMgef5KxAkb0DyG1Suy0qUo/qhz4c fd+yvsMvuwNKIgtSg2Mwh1OxyqtemWrCR313CI/E83x4HMETAwGwE1p/x0O+92+74LVQCA3 seBBwTwgp1WttZiWC9ZuZhuk2+Il5XxnVhl7iociEyPP58qCKJkaBSUq3Y1PKo44Yeb0LHI 8ANJsAlE+qDkPwWeAf4cNMObu+6H8T1LgidWOy7I4n4ndSjG74GJkIxAlXCVM9WHjH+VQcB B+/Hwppb8pA1dUO2o9npyP6Wf5p5a2rk+h+dhb0ratOHlx/viDP9tJTle2hu6AGG3DV+eVS ktTVEdDvsVLs2HKxrZH+U0O+UFs3V7dUt29FL4IduYYR8xBIsYWCjXqo3EbEELYMMUi8Spi w== X-QQ-XMRINFO: MSVp+SPm3vtSI1QTLgDHQqIV1w2oNKDqfg== X-QQ-RECHKSPAM: 0 Fix two issues in btintel_pcie_msix_tx_handle(): 1. cr_tia is a device-controlled value from shared DMA memory (data->ia.cr_tia[]) and is used to index txq->urbd0s[] without a bounds check. An out-of-range value could cause an out-of-bounds access when indexing txq->urbd0s[]. Add a bounds check before the array access. When cr_tia is out of range, reset the ring consumer pointer (data->ia.cr_tia[]) to cr_hia so the queue can recover on the next interrupt. 2. The existing check on urbd0->tfd_index uses '>' instead of '>=3D', allowing tfd_index =3D=3D txq->count (32) to pass. This check guards against a device-controlled value, so the comparison must reject all out-of-range indices. Read tfd_index via READ_ONCE() to ensure a single atomic read from DMA-coherent memory. Fixes: c2b636b3f788 ("Bluetooth: btintel_pcie: Add support for PCIe transpo= rt") Signed-off-by: ZhaoJinming --- drivers/bluetooth/btintel_pcie.c | 30 +++++++++++++++++++++++++++--- 1 file changed, 27 insertions(+), 3 deletions(-) diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_p= cie.c index fe50c5699e12ef3819577e0f0bd1b79d4340bd9e..c1fd5feb9f81bbd70fabd12b12e= b4a1708f6a91f 100644 --- a/drivers/bluetooth/btintel_pcie.c +++ b/drivers/bluetooth/btintel_pcie.c @@ -1081,9 +1081,10 @@ static void btintel_pcie_msix_gp0_handler(struct bti= ntel_pcie_data *data) */ static void btintel_pcie_msix_tx_handle(struct btintel_pcie_data *data) { - u16 cr_tia, cr_hia; + u16 cr_tia, cr_hia, tfd_index; struct txq *txq; struct urbd0 *urbd0; + struct hci_dev *hdev =3D data->hdev; =20 cr_tia =3D data->ia.cr_tia[BTINTEL_PCIE_TXQ_NUM]; cr_hia =3D data->ia.cr_hia[BTINTEL_PCIE_TXQ_NUM]; @@ -1094,13 +1095,36 @@ static void btintel_pcie_msix_tx_handle(struct btin= tel_pcie_data *data) txq =3D &data->txq; =20 while (cr_tia !=3D cr_hia) { + if (cr_tia >=3D txq->count) { + bt_dev_err(hdev, "TXQ: invalid cr_tia %u >=3D %u, contact device vendor= ", + cr_tia, txq->count); + /* Reset consumer pointer so the ring can + * recover on the next interrupt. + */ + data->ia.cr_tia[BTINTEL_PCIE_TXQ_NUM] =3D cr_hia; + break; + } + data->tx_wait_done =3D true; wake_up(&data->tx_wait_q); =20 urbd0 =3D &txq->urbd0s[cr_tia]; =20 - if (urbd0->tfd_index > txq->count) - return; + /* tfd_index is a bitfield in DMA-coherent memory; + * read the full word once with READ_ONCE to avoid + * TOCTOU race with the device. + */ + tfd_index =3D READ_ONCE(*(const u32 *)urbd0) & 0xffff; + + if (tfd_index >=3D txq->count) { + bt_dev_err(hdev, "TXQ: invalid tfd_index %u >=3D %u, contact device ven= dor", + tfd_index, txq->count); + /* Device provided invalid data. Leave cr_tia + * unchanged so the error remains detectable + * via repeated log messages, aiding debug. + */ + break; + } =20 cr_tia =3D (cr_tia + 1) % txq->count; data->ia.cr_tia[BTINTEL_PCIE_TXQ_NUM] =3D cr_tia; --=20 2.51.0 From nobody Mon Sep 28 16:22:44 2026 Received: from smtpbgbr2.qq.com (smtpbgbr2.qq.com [54.207.22.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9A92335836E; Thu, 20 Aug 2026 09:19:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=54.207.22.56 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787217576; cv=none; b=fQYOxyaBWiLWW5mS2OGJmgNsFHQOFd0uX/vpGN7mEVzYknGP9iZoLbPhXHZKb9pE6CWkQLEmThu5/dK58nVOUR7dNYnPxNqI6ExW5DHhuUxTcv/OsLgq1dVGEZNEtkLSrXvoakxGPDEJKDdxUuTnO3ZQ0F3RKDuIRw/2Yqalh+A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787217576; c=relaxed/simple; bh=nOtss0TxCtmWdavoL7v9pn+0B0ICzGQGg10gKsPVpVI=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=a7zHtA2gHEnnpAUvGlk51jkkwVCNI6BmU5S/WLe3iwTLyLR6CtCokVdntBmlro6C2WW5GOs8SQaX1nZMw4lB8zXR3bwXbb8G5MG1w/niZ8pQTwjcCIh+oC1y0Fc9nAt+DMWXMZboWW0+UpBCTzuXDafm5cQyetwCmpNsk2hQCf4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uniontech.com; spf=pass smtp.mailfrom=uniontech.com; dkim=pass (1024-bit key) header.d=uniontech.com header.i=@uniontech.com header.b=RqF6TXdw; arc=none smtp.client-ip=54.207.22.56 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uniontech.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=uniontech.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=uniontech.com header.i=@uniontech.com header.b="RqF6TXdw" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=uniontech.com; s=onoh2408; t=1787217535; bh=GoEKBmJAt8A3ik2//Pv/SnjBVCtMlg5xJdeBJ33wumM=; h=From:Date:Subject:MIME-Version:Message-Id:To; b=RqF6TXdwW4HPgmVA/Su6gENwOYS7vSsO7ODvb36H0FkgrmGR0goWPEGwbxz7/ABL6 Hy00IIzedMWKdQZoKPWVrEoS481ds/kHW7Dkpa90lmfxoOM2JvKCnOTftAPcG8xmoW 22KDo4Msbq9t6ReCCrtmEFGCKZXMbmSSf0rAIOGY= X-QQ-mid: zesmtpgz4t1787217527t383c08ee X-QQ-Originating-IP: yAWf75JrCXRBpkI+bEOJlyQKFVf9z7Y1+lPGW1bKpII= Received: from [10.10.7.64] ( [1.202.39.170]) by bizesmtp.qq.com (ESMTP) with id ; Thu, 20 Aug 2026 17:18:46 +0800 (CST) X-QQ-SSF: 0000000000000000000000000000000 X-QQ-GoodBg: 1 X-BIZMAIL-ID: 1403180757750471603 From: ZhaoJinming Date: Thu, 20 Aug 2026 17:17:40 +0800 Subject: [PATCH 3/3] Bluetooth: btintel_pcie: Fix bounds checks in RX completion handler Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260820-btintel_pcie_bounds_fixes-v1-3-c9dcd1ac8bf6@uniontech.com> References: <20260820-btintel_pcie_bounds_fixes-v1-0-c9dcd1ac8bf6@uniontech.com> In-Reply-To: <20260820-btintel_pcie_bounds_fixes-v1-0-c9dcd1ac8bf6@uniontech.com> To: Luiz Augusto von Dentz , Marcel Holtmann , Paul Menzel Cc: linux-bluetooth@vger.kernel.org, linux-kernel@vger.kernel.org X-Mailer: b4 0.14.2 X-QQ-SENDSIZE: 520 Feedback-ID: zesmtpgz:uniontech.com:qybglogicsvrsz:qybglogicsvrsz4b-0 X-QQ-XMAILINFO: MdzdX6p4PZzklCHKoGpLZBbFi7kvlpQe8XtDNQkiiOv8o7YodMQJHV70 DUNxjC5iGkdpsuLgP4KSzgZQyJtXXwkdZ5TeN/Dn9wSC3HhgzrHg7rq0K7ldICNJYs4mNRq VpmkdO7XvqQoF+g8D6/4WNFALCAfuD9TarvS+LXqAzycEyPtRRmu/fJspEaLnnIYNsCEw+R 38+rZy9gJjg2ToP5RLTcZnkl3SvNGno+DND6viiNv6bscus9WFPTnuKU7/IhB//8eeuocMn NzSQvEjl/up+UKShr+Wj7wN/4bLPCjN0jN6PYsgOXnO6SVxdsMdnUNq/S8suw5DuXi60nlU XSVgyX8+RYV733kkkNkk6WkQrAIw8f96VmPUstudU3in4zee4W12JsZy2HLfTmVjMJfTgr9 NWWVkW4xbAyx6UKcPxdpxC89iVdnBA0+aBy0bzW93AgP4RgIA0R6hnG8hZ0x0iYfyDncRuK slt/+4wKdnzC5ohoowYmUUKdYGKt54ufpDPiIU2m2abmfRVG3CPFNLI45EJidFzMo3pYTxS 8hpEDh4/llJzdtnnzvWT7uaeJzZO6oQCM6tbiEOJlgCbd+Am44eWzYNCcQfaQ4QvYebdleL 0ml8o6n5KKmwwsckeROy4m5bx2VKKeSLYq5FloqOqqEQ05o/aLDH8sZ/JU3Gpqw/6rVmBbu pQFKL7sxpyVPF857zYgE7MCr5emv60SRx1N2BUJbE8uSoQmSZHL8hBhrlHsK8Fz8RO6QsMJ TK8PkxMU/AKPKs65X8lOrBKGB3uvhySYeVFh5XjfEG/WXxZgxE+5SEpvJthzPWAjDilUzU+ z7f3hS6vl966zCwzA0OGmUI2nv7r/mmZIqrqAXkE+s8VGXsYwgSu+VOq1iVbKl6qVu7HHRs fjPQXm6Gp33iLEKduhf7F7UXZBIhu7kPRf/6TW/dRdmgDthHD4t7S+sUyr5lV23z+Sj4cd0 sQZ8p8n/TbME6kWNEPhT2rMMec8HsY4st+OpamcHn85Mo37JWy5YDAUE5rm5He6Y9nKXCRi 6o+Bdm/4EEH32PwLG9NQbZBydLTgWokJNdDAMlBteR7UkhxjQc X-QQ-XMRINFO: NyFYKkN4Ny6FuXrnB5Ye7Aabb3ujjtK+gg== X-QQ-RECHKSPAM: 0 Fix three issues in btintel_pcie_msix_rx_handle(): 1. cr_tia is a device-controlled value from shared DMA memory (data->ia.cr_tia[]) and is used to index rxq->urbd1s[] without a bounds check. An out-of-range value could cause an out-of-bounds access when indexing rxq->urbd1s[]. Add a bounds check before the array access. When cr_tia is out of range, reset the ring consumer pointer (data->ia.cr_tia[]) to cr_hia so the queue can recover on the next interrupt. 2. urbd1->frbd_tag is a 16-bit device-controlled field (0-65535) used directly as an index into rxq->bufs[] (64 elements). Add a bounds check. Read the field via READ_ONCE() to avoid a Time-of-Check to Time-of-Use (TOCTOU) race, since the field is in DMA-coherent memory and the compiler may emit two separate reads. 3. All error paths in the while loop use 'return', which exits the handler without advancing cr_tia. This causes the RX completion queue to stall, as the next interrupt would process the same corrupted descriptor and exit again. Change to 'break' to exit the loop without further processing. Fixes: c2b636b3f788 ("Bluetooth: btintel_pcie: Add support for PCIe transpo= rt") Signed-off-by: ZhaoJinming --- drivers/bluetooth/btintel_pcie.c | 44 ++++++++++++++++++++++++++++++++++--= ---- 1 file changed, 38 insertions(+), 6 deletions(-) diff --git a/drivers/bluetooth/btintel_pcie.c b/drivers/bluetooth/btintel_p= cie.c index c1fd5feb9f81bbd70fabd12b12eb4a1708f6a91f..1f5537df620972d937f65e75470= 1f65566e4655a 100644 --- a/drivers/bluetooth/btintel_pcie.c +++ b/drivers/bluetooth/btintel_pcie.c @@ -1586,7 +1586,7 @@ static int btintel_pcie_submit_rx_work(struct btintel= _pcie_data *data, u8 status /* Handles the MSI-X interrupt for rx queue 1 which is for RX */ static void btintel_pcie_msix_rx_handle(struct btintel_pcie_data *data) { - u16 cr_hia, cr_tia; + u16 cr_hia, cr_tia, frbd_tag; struct rxq *rxq; struct urbd1 *urbd1; struct data_buf *buf; @@ -1608,21 +1608,53 @@ static void btintel_pcie_msix_rx_handle(struct btin= tel_pcie_data *data) * process all received CDs in this interrupt. */ while (cr_tia !=3D cr_hia) { + if (cr_tia >=3D rxq->count) { + bt_dev_err(hdev, "RXQ: invalid cr_tia %u >=3D %u, contact device vendor= ", + cr_tia, rxq->count); + /* Reset consumer pointer so the ring can + * recover on the next interrupt. + */ + data->ia.cr_tia[BTINTEL_PCIE_RXQ_NUM] =3D cr_hia; + break; + } + urbd1 =3D &rxq->urbd1s[cr_tia]; ipc_print_urbd1(data->hdev, urbd1, cr_tia); =20 - buf =3D &rxq->bufs[urbd1->frbd_tag]; + /* frbd_tag is a bitfield in DMA-coherent memory; + * read the full word once with READ_ONCE to avoid + * TOCTOU race with the device. + */ + frbd_tag =3D READ_ONCE(*(const u32 *)urbd1) & 0xffff; + + if (frbd_tag >=3D rxq->count) { + bt_dev_err(hdev, "RXQ: invalid frbd_tag %u >=3D %u, contact device vend= or", + frbd_tag, rxq->count); + /* Device provided invalid data. Leave cr_tia + * unchanged so the error remains detectable + * via repeated log messages, aiding debug. + */ + break; + } + + buf =3D &rxq->bufs[frbd_tag]; if (!buf) { - bt_dev_err(hdev, "RXQ: failed to get the DMA buffer for %d", - urbd1->frbd_tag); - return; + bt_dev_err(hdev, "RXQ: failed to get the DMA buffer for %u", + frbd_tag); + /* Unexpected NULL pointer; leave cr_tia + * unchanged to keep the error visible. + */ + break; } =20 ret =3D btintel_pcie_submit_rx_work(data, urbd1->status, buf->data); if (ret) { bt_dev_err(hdev, "RXQ: failed to submit rx request"); - return; + /* Submission failed; leave cr_tia unchanged + * to keep the error detectable on retry. + */ + break; } =20 cr_tia =3D (cr_tia + 1) % rxq->count; --=20 2.51.0