Back

HIGH

selinux: check connect-related permissions on TCP Fast Open

Published Aug 15, 2026

Description

Similar to Landlock, SELinux was not updated when TCP Fast Open support was introduced to ensure connect-related permissions are checked when using TCP Fast Open. Update its socket_sendmsg() hook to call selinux_socket_connect() when MSG_FASTOPEN is passed.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, TCP Fast Open (TFO) can be disabled if not required by applications. Disabling TFO prevents the vulnerable code path from being exercised, thereby eliminating the SELinux permission bypass. To disable TCP Fast Open: 1. Check the current setting: `sysctl net.ipv4.tcp_fastopen` 2. To disable it temporarily: `sudo sysctl -w net.ipv4.tcp_fastopen=0` 3. To make the change persistent across reboots, add or modify the following line in `/etc/sysctl.conf`: `net.ipv4.tcp_fastopen = 0` 4. Apply the persistent changes: `sudo sysctl -p` Disabling TCP Fast Open may impact the performance of applications that utilize this feature for faster connection establishment.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Aug 15, 2026
Updated Aug 18, 2026
Reserved Aug 9, 2026
NVD
Status Received
Modified Aug 18, 2026
Red Hat
Severity Important
Public date Aug 15, 2026