{"id":"CVE-2025-38629","summary":"ALSA: usb: scarlett2: Fix missing NULL check","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb: scarlett2: Fix missing NULL check\n\nscarlett2_input_select_ctl_info() sets up the string arrays allocated\nvia kasprintf(), but it misses NULL checks, which may lead to NULL\ndereference Oops.  Let's add the proper NULL check.","modified":"2026-04-02T12:48:03.390542Z","published":"2025-08-22T16:00:37.747Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38629.json","cna_assigner":"Linux"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2c735fcaee81ad8056960659dc9dc460891e76b0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d558db85920b124bac36f8a7ddc5de0aa7491bdd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/df485a4b2b3ee5b35c80f990beb554e38a8a5fb1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38629.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-38629"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"8eba063b5b2b498ddd01ea6f29fc9b12368c3d53"},{"fixed":"d558db85920b124bac36f8a7ddc5de0aa7491bdd"},{"fixed":"2c735fcaee81ad8056960659dc9dc460891e76b0"},{"fixed":"df485a4b2b3ee5b35c80f990beb554e38a8a5fb1"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38629.json"}}],"schema_version":"1.7.5"}