Executive brief
A vulnerability in the Linux kernel's AppArmor security module could allow restricted applications to bypass network connection rules. By using a specific networking feature called 'TCP Fast Open,' a program that is supposed to be blocked from making new connections could still successfully reach out to other systems. This undermines the security boundaries intended to isolate potentially untrusted software.
Technical details
A vulnerability exists in the AppArmor Linux Security Module (LSM) where it fails to mediate implicit connection requests initiated via sendmsg() or sendto() with the MSG_FASTOPEN flag. While AppArmor checks for 'send' permissions (AA_MAY_SEND), it does not verify 'connect' permissions (AA_MAY_CONNECT) during these specific system calls. This allows a confined task with a profile that grants 'send' but denies 'connect' to establish outbound TCP or MPTCP connections. The fix involves updating apparmor_socket_sendmsg() to explicitly call aa_sk_perm() for connection mediation when MSG_FASTOPEN is set and a destination is provided. This issue affects Linux kernels from version 3.6 up to the patched stable releases.
Affected products
- Linux Linux Kernel 3.6 to 6.18.38
Timeline
- 2026-06-22: other: Vulnerability fix authored
- 2026-07-04: patched: Fix committed to stable kernel tree
- 2026-07-19: disclosed: CVE-2026-63828 published
References
- https://git.kernel.org/stable/c/07b71c342382b854ab8030b244aeab6a7228ad7d
- https://git.kernel.org/stable/c/45ebb934ea50b436ce49b2f159f090dab0d7fa28
- https://git.kernel.org/stable/c/4a69b83045d3195d5b9a9b053ad840ddb2998b4e
- https://git.kernel.org/stable/c/4d587cd8a72155089a627130bbd4716ec0856e21
- https://git.kernel.org/stable/c/7f57428ce00891d26b0f087ef754a4d820ec83aa
- https://git.kernel.org/stable/c/faea60deaa05c76f0772650f42eafde12bd39d93