Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-72243

CVE-2026-72243: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.3

    High [CVE-2026-72243] check connect-related permissions on TCP Fast Open

    CVE-2026-72243Source published Source updated

    In the Linux kernel, the following vulnerability has been resolved: selinux: check connect-related permissions on TCP Fast Open Similar to Landlock, SELinux was not updated when TCP Fast Open support was introduced to ensure connect-related permissions are checked when using TCP Fast Open. Update its socket_sendmsg() hook to call selinux_socket_connect() when MSG_FASTOPEN is passed. This oversight could allow a local attacker to bypass SELinux network access controls, potentially enabling unauthorized network connections that should have been restricted by security policies. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L). Weakness: CWE-551. Affected Red Hat products: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux…

    Affected products in this advisory
    • Red Hat Enterprise Linux 9
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 6
    • Red Hat Enterprise Linux 7

    2 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • kernel-0:5.14.0-687.49.1.el9_8
    • RHSA-2026:68570
    Mitigation guidance
    • To mitigate this issue, TCP Fast Open (TFO) can be disabled if not required by applications. Disabling TFO prevents the vulnerable code path from being exercised, thereby eliminating the SELinux permission bypass. To disable TCP Fast Open: 1. Check the current setting: `sysctl net.ipv4.tcp_fastopen` 2. To disable it temporarily: `sudo sysctl -w net.ipv4.tcp_fastopen=0` 3. To make the change persistent across reboots, add or modify the following line in `/etc/sysctl.conf`: `net.ipv4.tcp_fastopen = 0` 4. Apply the persistent changes: `sudo sysctl -p` Disabling TCP Fast Open may impact the performance of applications that utilize this feature for faster connection establishment.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery