In this line we assume that dst_sec can be NULL: https://kernel.googlesource.com/pub/scm/linux/kernel/git/bpf/bpf-next/+/refs/heads/master/tools/lib/bpf/linker.c#2160 But after we use it without check: https://kernel.googlesource.com/pub/scm/linux/kernel/git/bpf/bpf-next/+/refs/heads/master/tools/lib/bpf/linker.c#2167 Can we get CWE-476 here? Best regards, Egor.