8.4
CVE-2026-63828
- EPSS 0.13%
- Veröffentlicht 19.07.2026 12:02:22
- Zuletzt bearbeitet 17.08.2026 05:17:20
- CVE-Watchlists
- Unerledigt
apparmor: mediate the implicit connect of TCP fast open sendmsg
In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connection in the SYN. apparmor_socket_sendmsg() only checks AA_MAY_SEND, so a profile that grants send but denies connect lets a confined task open an outbound TCP/MPTCP connection that connect(2) would have refused, bypassing connect mediation. Mediate the implicit connect when MSG_FASTOPEN is set and a destination is supplied. Add it to apparmor_socket_sendmsg() (not the shared aa_sock_msg_perm() helper, which recvmsg also uses) and call aa_sk_perm() directly, mirroring the selinux and tomoyo fixes. sk_is_tcp() does not cover MPTCP fast open, so the SOCK_STREAM/IPPROTO_MPTCP arm is explicit.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
cf60af03ca4e71134206809ea892e49b92a88896
Version <
a16714e7cf2baa98ba2efddd5d6cbac641f4e76b
Status
affected
Version
cf60af03ca4e71134206809ea892e49b92a88896
Version <
20383429b56974507c465d016e5238b189f7a246
Status
affected
Version
cf60af03ca4e71134206809ea892e49b92a88896
Version <
7f57428ce00891d26b0f087ef754a4d820ec83aa
Status
affected
Version
cf60af03ca4e71134206809ea892e49b92a88896
Version <
faea60deaa05c76f0772650f42eafde12bd39d93
Status
affected
Version
cf60af03ca4e71134206809ea892e49b92a88896
Version <
07b71c342382b854ab8030b244aeab6a7228ad7d
Status
affected
Version
cf60af03ca4e71134206809ea892e49b92a88896
Version <
4a69b83045d3195d5b9a9b053ad840ddb2998b4e
Status
affected
Version
cf60af03ca4e71134206809ea892e49b92a88896
Version <
45ebb934ea50b436ce49b2f159f090dab0d7fa28
Status
affected
Version
cf60af03ca4e71134206809ea892e49b92a88896
Version <
4d587cd8a72155089a627130bbd4716ec0856e21
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.6
Status
affected
Version
0
Version <
3.6
Status
unaffected
Version <=
5.10.*
Version
5.10.261
Status
unaffected
Version <=
5.15.*
Version
5.15.212
Status
unaffected
Version <=
6.1.*
Version
6.1.177
Status
unaffected
Version <=
6.6.*
Version
6.6.144
Status
unaffected
Version <=
6.12.*
Version
6.12.95
Status
unaffected
Version <=
6.18.*
Version
6.18.38
Status
unaffected
Version <=
7.1.*
Version
7.1.3
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.031 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.4 | 2 | 5.8 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
|
https://git.kernel.org/stable/c/7f57428ce00891d26b0f087ef754a4d820ec83aa
https://git.kernel.org/stable/c/faea60deaa05c76f0772650f42eafde12bd39d93
https://git.kernel.org/stable/c/07b71c342382b854ab8030b244aeab6a7228ad7d
https://git.kernel.org/stable/c/4a69b83045d3195d5b9a9b053ad840ddb2998b4e
https://git.kernel.org/stable/c/45ebb934ea50b436ce49b2f159f090dab0d7fa28
https://git.kernel.org/stable/c/4d587cd8a72155089a627130bbd4716ec0856e21
https://git.kernel.org/stable/c/20383429b56974507c465d016e5238b189f7a246
https://git.kernel.org/stable/c/a16714e7cf2baa98ba2efddd5d6cbac641f4e76b