Rule Category

PROTOCOL-RPC -- Snort has detected traffic that may indicate the presence of the rpc protocol or vulnerabilities in the rpc protocol on the network.

Alert Message

PROTOCOL-RPC FreeBSD NFS RPCSEC_GSS stack buffer overflow attempt

Rule Explanation

This rule looks for a malformed RPCSEC_GSS authentication packet sent to a vulnerable FreeBSD system.

What To Look For

This rule looks for attempts to exploit a buffer overflow vulnerability in the RPCSEC_GSS authentication of the kgssapi.ko module in FreeBSD systems.

Known Usage

Attacks/Scans seen in the wild

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application

Rule Categories::Protocol::RPC

Vulnerability::Severity::High

Vulnerability::Severity::Critical

CVE

Additional Links

Rule Vulnerability

Memory Corruption

Memory Corruption is any vulnerability that allows the modification of the content of memory locations in a way not intended by the developer. Memory corruption results are inconsistent; they could lead to fatal errors and system crashes or data leakage; some have no effect at all.

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2026-4747
Loading description