OS-LINUX -- Snort has detected traffic targeting vulnerabilities in a Linux-based operating system. This does not include browser traffic or other software on the OS, but attacks against the OS itself. (such as?)
OS-LINUX Linux kernel af_packet tpacket_rcv integer overflow attempt
This rule looks for crafted Linux binaries designed to trigger an integer overflow vulnerability in the Linux Kernel.
This rule looks for crafted Linux binaries designed to trigger an integer overflow vulnerability in the Linux Kernel.
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
N/A
Not Applicable
CVE-2020-14386A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity. |
|
Tactic: Privilege Escalation
Technique: Exploitation for Privilege Escalation
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org