[PATCH] apparmor: check connect permission for SCTP

sashiko-bot at kernel.org sashiko-bot at kernel.org
Fri Sep 25 19:46:01 UTC 2026


> SCTP can start an association through sendmsg() or CONNECTX. These paths
> call the SCTP-specific sctp_bind_connect hook instead of the normal socket
> connect hook, but AppArmor does not register it. As a result, a profile can
> deny connect and allow send or setopt, yet a task can still create an SCTP
> association.
> 
> Register the SCTP hook. Ask for connect permission when SENDMSG_CONNECT
> or CONNECTX creates an association.
> 
> Fixes: 56974a6fcfef ("apparmor: add base infastructure for socket mediation")
> Assisted-by: LLM
> Signed-off-by: Jérémy Jean <Jeremy.Jean at oss.cyber.gouv.fr>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260925193842.1208132-3-Jeremy.Jean@oss.cyber.gouv.fr?part=1




More information about the Linux-security-module-archive mailing list