Answer in brief
CVE-2026-63828 records a High severity (CVSS 8.4) vulnerability in apparmor: mediate the implicit connect of TCP fast open sendmsg. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=cf60af03ca4e71134206809ea892e49b92a88896 <a16714e7cf2baa98ba2efddd5d6cbac641f4e76b || >=cf60af03ca4e71134206809ea892e49b92a88896 <20383429b56974507c465d016e5238b189f7a246 || >=cf60af03ca4e71134206809ea892e49b92a88896 <7f57428ce00891d26b0f087ef754a4d820ec83aa || >=cf60af03ca4e71134206809ea892e49b92a88896 <faea60deaa05c76f0772650f42eafde12bd39d93 || >=cf60af03ca4e71134206809ea892e49b92a88896 <07b71c342382b854ab8030b244aeab6a7228ad7d || >=cf60af03ca4e71134206809ea892e49b92a88896 <4a69b83045d3195d5b9a9b053ad840ddb2998b4e || >=cf60af03ca4e71134206809ea892e49b92a88896 <45ebb934ea50b436ce49b2f159f090dab0d7fa28 || >=cf60af03ca4e71134206809ea892e49b92a88896 <4d587cd8a72155089a627130bbd4716ec0856e21 | a16714e7cf2baa98ba2efddd5d6cbac641f4e76b, 20383429b56974507c465d016e5238b189f7a246, 7f57428ce00891d26b0f087ef754a4d820ec83aa, faea60deaa05c76f0772650f42eafde12bd39d93, 07b71c342382b854ab8030b244aeab6a7228ad7d, 4a69b83045d3195d5b9a9b053ad840ddb2998b4e, 45ebb934ea50b436ce49b2f159f090dab0d7fa28, 4d587cd8a72155089a627130bbd4716ec0856e21 |
| Linux/Linuxgeneric | 3.6 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connection in the SYN. apparmor_socket_sendmsg() only checks AA_MAY_SEND, so a profile that grants send but denies connect lets a confined task open an outbound TCP/MPTCP connection that connect(2) would have refused, bypassing connect mediation. Mediate the implicit connect when MSG_FASTOPEN is set and a destination is supplied. Add it to apparmor_socket_sendmsg() (not the shared aa_sock_msg_perm() helper, which recvmsg also uses) and call aa_sk_perm() directly, mirroring the selinux and tomoyo fixes. sk_is_tcp() does not cover MPTCP fast open, so the SOCK_STREAM/IPPROTO_MPTCP arm is explicit.
Quoted source text, attributed separately from HOL analysis.