SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-63828

HIGH · CVSS 8.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel allows confined tasks to bypass connection mediation when using TCP Fast Open with the sendmsg() or sendto() functions, potentially enabling unauthorized outbound TCP/MPTCP connections. This flaw could lead to security policy violations, as it allows processes with restricted permissions to establish connections that should be denied. Organizations utilizing Linux systems with AppArmor should prioritize patching this vulnerability to maintain their security posture.

CVE
CVE-2026-63828
Severity
HIGH
CVSS
8.4
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connection in the SYN. apparmor_socket_sendmsg() only checks AA_MAY_SEND, so a profile that grants send but denies connect lets a confined task open an outbound TCP/MPTCP connection that connect(2) would have refused, bypassing connect mediation. Mediate the implicit connect when MSG_FASTOPEN is set and a destination is supplied. Add it to apparmor_socket_sendmsg() (not the shared aa_sock_msg_perm() helper, which recvmsg also uses) and call aa_sk_perm() directly, mirroring the selinux and tomoyo fixes. sk_is_tcp() does not cover MPTCP fast open, so the SOCK_STREAM/IPPROTO_MPTCP arm is explicit.