Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

Detects attempts to grant world-writable (0666) permissions to the /dev/kvm device node using chmod or setfacl, or unauthorized (non-root) accounts interacting directly with the device. Such configuration changes are associated with the Januscape (CVE-2026-53359) vulnerability, which allows local users to exploit a shadow MMU use-after-free in the kernel to escalate privileges to root or escape into the host from a virtualized environment.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
3 months ago
4018
Identifies Linux systems acting as KVM hypervisors that are running kernels vulnerable to CVE-2026-53359 (Januscape), a use-after-free vulnerability in the shadow MMU (arch/x86/kvm/mmu/mmu.c). This vulnerability permits a guest virtual machine to escape into the underlying host environment, potentially compromising the hypervisor and other hosted workloads.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
3 months ago
7012