Rule Category

OS-LINUX -- Snort has detected traffic targeting vulnerabilities in a Linux-based operating system. This does not include browser traffic or other software on the OS, but attacks against the OS itself. (such as?)

Alert Message

OS-LINUX Linux Kernel Dirty Frag privilege escalation attempt

Rule Explanation

This rule looks for a specific sequence of bytes associated with Dirty Frag exploit payloads. Successful exploitation can grant root privileges on affected Linux systems.

What To Look For

This rule fires on attempts to exploit a local privilege escalation vulnerability in the Linux Kernel.

Known Usage

Public information/Proof of Concept available

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

Rule Vulnerability

Escalation of Privilege

An Escalation of Privilege (EOP) attack is any attack method that results in a user or application gaining permissions to access resources they normally would not have access to.

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2026-43284
Loading description
CVE-2026-43500
Loading description