selinux: check connect-related permissions on TCP Fast Open
Published Aug 15, 2026
8.4
HIGHCVSS 3.1
EPSS 0.17%
Description
Similar to Landlock, SELinux was not updated when TCP Fast Open support was introduced to ensure connect-related permissions are checked when using TCP Fast Open. Update its socket_sendmsg() hook to call selinux_socket_connect() when MSG_FASTOPEN is passed.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.6StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.6
- Version 6.1.178StatusunaffectedConstraints<=6.1.*
- Version 6.12.97StatusunaffectedConstraints<=6.12.*
- Version 6.18.40StatusunaffectedConstraints<=6.18.*
- Version 6.6.145StatusunaffectedConstraints<=6.6.*
- Version 7.1.5StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.49.1.el9_8
Fixed · RHSA-2026:68570
Red Hat Enterprise Linux 9
kernel-0:5.14.0-687.49.1.el9_8
Fixed · RHSA-2026:68570
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Affected
Red Hat Enterprise Linux 7
kernel
Affected
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Will not fix
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.49.1.el9_8 | Fixed | RHSA-2026:68570 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-687.49.1.el9_8 | Fixed | RHSA-2026:68570 |
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, TCP Fast Open (TFO) can be disabled if not required by applications. Disabling TFO prevents the vulnerable code path from being exercised, thereby eliminating the SELinux permission bypass. To disable TCP Fast Open: 1. Check the current setting: `sysctl net.ipv4.tcp_fastopen` 2. To disable it temporarily: `sudo sysctl -w net.ipv4.tcp_fastopen=0` 3. To make the change persistent across reboots, add or modify the following line in `/etc/sysctl.conf`: `net.ipv4.tcp_fastopen = 0` 4. Apply the persistent changes: `sudo sysctl -p` Disabling TCP Fast Open may impact the performance of applications that utilize this feature for faster connection establishment.
References (11)
- https://access.redhat.com/security/cve/CVE-2026-72243 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2516684 Issue Tracking
- https://git.kernel.org/stable/c/11406d0d7e11b4e525bb2ace2c70107031d058da
- https://git.kernel.org/stable/c/44c74d27d1b9aaa99fa8a83640c1223575262b80
- https://git.kernel.org/stable/c/646ebbc5f2ff9147d084e1213143f091026a611c
- https://git.kernel.org/stable/c/d028bc080a0dcd6a7f8e1ae1bd32dda696505ba3
- https://git.kernel.org/stable/c/e507633bf76bccf1a6af27771fb0d6e2862b7eac
- https://git.kernel.org/stable/c/fc633a598206d4f23af782db7c0b5f3a82751d2c
- https://lore.kernel.org/linux-cve-announce/2026081551-CVE-2026-72243-04e7@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-72243
- https://www.cve.org/CVERecord?id=CVE-2026-72243
Change history (0)
No recorded changes yet.