{"id":"CVE-2022-3606","details":"A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to apply a patch to fix this issue. The identifier VDB-211749 was assigned to this vulnerability.","modified":"2026-03-13T05:54:34.622947Z","published":"2022-10-19T09:15:10.037Z","related":["SUSE-SU-2023:0405-1","SUSE-SU-2023:0409-1","SUSE-SU-2023:0779-1","openSUSE-SU-2024:12491-1"],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00033.html"},{"type":"ADVISORY","url":"https://vuldb.com/?id.211749"},{"type":"FIX","url":"https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=d0d382f95a9270dcf803539d6781d6bd67e3f5b2"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-3606.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"6.2"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}