Rule Category

OS-LINUX -- Snort has detected traffic targeting vulnerabilities in a Linux-based operating system. This does not include browser traffic or other software on the OS, but attacks against the OS itself. (such as?)

Alert Message

OS-LINUX Linux Kernel Dirty Frag privilege escalation attempt

Rule Explanation

This rule looks for a specific sequence of binary instructions associated with the Dirty Frag exploit within file data. Successful exploitation grants root privileges on the affected system.

What To Look For

This rule fires on attempts to exploit a Linux kernel privilege escalation vulnerability known as Dirty Frag.

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

Rule Vulnerability

Escalation of Privilege

An Escalation of Privilege (EOP) attack is any attack method that results in a user or application gaining permissions to access resources they normally would not have access to.

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2026-43284
Loading description
CVE-2026-43500
Loading description