{"id":"CVE-2025-38629","summary":"ALSA: usb: scarlett2: Fix missing NULL check","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb: scarlett2: Fix missing NULL check\n\nscarlett2_input_select_ctl_info() sets up the string arrays allocated\nvia kasprintf(), but it misses NULL checks, which may lead to NULL\ndereference Oops.  Let's add the proper NULL check.","modified":"2026-05-15T11:54:17.782725613Z","published":"2025-08-22T16:00:37.747Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38629.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2c735fcaee81ad8056960659dc9dc460891e76b0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d558db85920b124bac36f8a7ddc5de0aa7491bdd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/df485a4b2b3ee5b35c80f990beb554e38a8a5fb1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38629.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-38629"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.15.10"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.16.0"},{"fixed":"6.16.1"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38629.json"}}],"schema_version":"1.7.5"}