CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel allows confined tasks to bypass connection mediation when using TCP Fast Open with the sendmsg() or sendto() functions, potentially enabling unauthorized outbound TCP/MPTCP connections. This flaw could lead to security policy violations, as it allows processes with restricted permissions to establish connections that should be denied. Organizations utilizing Linux systems with AppArmor should prioritize patching this vulnerability to maintain their security posture.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connection in the SYN. apparmor_socket_sendmsg() only checks AA_MAY_SEND, so a profile that grants send but denies connect lets a confined task open an outbound TCP/MPTCP connection that connect(2) would have refused, bypassing connect mediation. Mediate the implicit connect when MSG_FASTOPEN is set and a destination is supplied. Add it to apparmor_socket_sendmsg() (not the shared aa_sock_msg_perm() helper, which recvmsg also uses) and call aa_sk_perm() directly, mirroring the selinux and tomoyo fixes. sk_is_tcp() does not cover MPTCP fast open, so the SOCK_STREAM/IPPROTO_MPTCP arm is explicit.