8.4

CVE-2026-63828

apparmor: mediate the implicit connect of TCP fast open sendmsg

In the Linux kernel, the following vulnerability has been resolved:

apparmor: mediate the implicit connect of TCP fast open sendmsg

sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and
write(2): it opens the connection in the SYN. apparmor_socket_sendmsg()
only checks AA_MAY_SEND, so a profile that grants send but denies connect
lets a confined task open an outbound TCP/MPTCP connection that connect(2)
would have refused, bypassing connect mediation.

Mediate the implicit connect when MSG_FASTOPEN is set and a destination
is supplied. Add it to apparmor_socket_sendmsg() (not the shared
aa_sock_msg_perm() helper, which recvmsg also uses) and call aa_sk_perm()
directly, mirroring the selinux and tomoyo fixes. sk_is_tcp() does not
cover MPTCP fast open, so the SOCK_STREAM/IPPROTO_MPTCP arm is explicit.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version cf60af03ca4e71134206809ea892e49b92a88896
Version < a16714e7cf2baa98ba2efddd5d6cbac641f4e76b
Status affected
Version cf60af03ca4e71134206809ea892e49b92a88896
Version < 20383429b56974507c465d016e5238b189f7a246
Status affected
Version cf60af03ca4e71134206809ea892e49b92a88896
Version < 7f57428ce00891d26b0f087ef754a4d820ec83aa
Status affected
Version cf60af03ca4e71134206809ea892e49b92a88896
Version < faea60deaa05c76f0772650f42eafde12bd39d93
Status affected
Version cf60af03ca4e71134206809ea892e49b92a88896
Version < 07b71c342382b854ab8030b244aeab6a7228ad7d
Status affected
Version cf60af03ca4e71134206809ea892e49b92a88896
Version < 4a69b83045d3195d5b9a9b053ad840ddb2998b4e
Status affected
Version cf60af03ca4e71134206809ea892e49b92a88896
Version < 45ebb934ea50b436ce49b2f159f090dab0d7fa28
Status affected
Version cf60af03ca4e71134206809ea892e49b92a88896
Version < 4d587cd8a72155089a627130bbd4716ec0856e21
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.6
Status affected
Version 0
Version < 3.6
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.177
Status unaffected
Version <= 6.6.*
Version 6.6.144
Status unaffected
Version <= 6.12.*
Version 6.12.95
Status unaffected
Version <= 6.18.*
Version 6.18.38
Status unaffected
Version <= 7.1.*
Version 7.1.3
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.031
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2 5.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7f57428ce00891d26b0f087ef754a4d820ec83aa
https://git.kernel.org/stable/c/faea60deaa05c76f0772650f42eafde12bd39d93
https://git.kernel.org/stable/c/07b71c342382b854ab8030b244aeab6a7228ad7d
https://git.kernel.org/stable/c/4a69b83045d3195d5b9a9b053ad840ddb2998b4e
https://git.kernel.org/stable/c/45ebb934ea50b436ce49b2f159f090dab0d7fa28
https://git.kernel.org/stable/c/4d587cd8a72155089a627130bbd4716ec0856e21
https://git.kernel.org/stable/c/20383429b56974507c465d016e5238b189f7a246
https://git.kernel.org/stable/c/a16714e7cf2baa98ba2efddd5d6cbac641f4e76b