[PATCH] nfc: st95hf: register NFC device after drvdata and locks are set up

From: Haotian Zhang

Date: Thu Oct 08 2026 - 23:17:57 EST


st95hf_probe() calls nfc_digital_register_device() before
nfc_digital_set_drvdata(). The nfc_digital_dev is allocated with
kzalloc(), so ddev->driver_data is still NULL when the device becomes
visible to userspace. A NFC_CMD_DEV_UP from userspace can then reach
digital_dev_up() -> digital_switch_rf() -> st95hf_switch_rf(), which gets
a NULL stcontext from nfc_digital_get_drvdata() and passes it to
st95hf_select_protocol()/rf_off(), dereferencing it. The exchange_lock
semaphore and rm_lock mutex used by the command paths are initialized
after registration for the same reason.

Set the driver data and initialize the locks before registering the
device.

Fixes: cab47333f0f7 ("NFC: Add STMicroelectronics ST95HF driver")
Assisted-by: DeepSeek-V4.1-Flash
Signed-off-by: Haotian Zhang <vulab@xxxxxxxxxxx>
---
drivers/nfc/st95hf/core.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)

diff --git a/drivers/nfc/st95hf/core.c b/drivers/nfc/st95hf/core.c
index 4d772a308bff..9f6a086653aa 100644
--- a/drivers/nfc/st95hf/core.c
+++ b/drivers/nfc/st95hf/core.c
@@ -1170,18 +1170,18 @@ static int st95hf_probe(struct spi_device *nfc_spi_dev)
st95context->nfcdev = st95context->ddev->nfc_dev;
nfc_digital_set_parent_dev(st95context->ddev, &nfc_spi_dev->dev);

- ret = nfc_digital_register_device(st95context->ddev);
- if (ret) {
- dev_err(&st95context->nfcdev->dev, "st95hf registration failed\n");
- goto err_free_digital_device;
- }
-
/* store st95context in nfc device object */
nfc_digital_set_drvdata(st95context->ddev, st95context);

sema_init(&st95context->exchange_lock, 1);
mutex_init(&st95context->rm_lock);

+ ret = nfc_digital_register_device(st95context->ddev);
+ if (ret) {
+ dev_err(&st95context->nfcdev->dev, "st95hf registration failed\n");
+ goto err_free_digital_device;
+ }
+
return ret;

err_free_digital_device:
--
2.25.1