File _patchinfo of Package patchinfo.27678

<patchinfo incident="27678">
  <issue tracker="bnc" id="1204502">VUL-0: CVE-2022-3606: kernel: null pointer dereference in find_prog_by_sec_insn() (tools/lib/bpf/libbpf.c)</issue>
  <issue tracker="bnc" id="1204391">VUL-0: CVE-2022-3534: libbpf: use-after-free in btf_dump_name_dups</issue>
  <issue tracker="cve" id="2022-3606"/>
  <issue tracker="cve" id="2022-3534"/>
  <packager>shunghsiyu</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for libbpf</summary>
  <description>This update for libbpf fixes the following issues:

  - CVE-2022-3534: Fixed use-after-free in btf_dump_name_dups (bsc#1204391).
  - CVE-2022-3606: Fixed null pointer dereference in find_prog_by_sec_insn() (bsc#1204502).
</description>
</patchinfo>
openSUSE Build Service is sponsored by