From 849489b94fe35172a4fea6e09acabacd273d8993 Mon Sep 17 00:00:00 2001 From: TsaiGaggery Date: Wed, 11 Mar 2026 14:21:39 -0700 Subject: [PATCH 17/17] ASoC: SDCA: Fix NULL pointer dereference in sdca_jack_process() Add NULL guard for card and card->snd_card before dereferencing. During card teardown, component->card can be NULL when an IRQ fires. --- diff --git a/sound/soc/sdca/sdca_jack.c b/sound/soc/sdca/sdca_jack.c index 49d317d..b52d88a 100644 --- a/sound/soc/sdca/sdca_jack.c +++ b/sound/soc/sdca/sdca_jack.c @@ -37,13 +37,21 @@ int sdca_jack_process(struct sdca_interrupt *interrupt) struct device *dev = interrupt->dev; struct snd_soc_component *component = interrupt->component; struct snd_soc_card *card = component->card; - struct rw_semaphore *rwsem = &card->snd_card->controls_rwsem; + struct rw_semaphore *rwsem; struct jack_state *state = interrupt->priv; - struct snd_kcontrol *kctl = state->kctl; + struct snd_kcontrol *kctl; struct snd_ctl_elem_value *ucontrol __free(kfree) = NULL; unsigned int reg, val; int ret; + if (!card || !card->snd_card) { + dev_dbg(dev, "card not yet bound, deferring jack event\n"); + return -ENODEV; + } + + rwsem = &card->snd_card->controls_rwsem; + kctl = state->kctl; + guard(rwsem_write)(rwsem); if (!kctl) {