[PATCH 0/3] x86/shstk: ban ia32 sigreturn
From: Richard Patel
Date: Thu Oct 08 2026 - 16:22:21 EST
User shadow stacks protect only the x64 and x32 rt_sigreturn syscalls.
Calling ia32 rt_sigreturn, which lacks return address validation, is
still possible via `int $0x80`. The bypass also requires the executable
is mapped into low 32-bit address space. (This scenario is basically
impossible to occur in the wild, but it's probably worth fixing
nonetheless.)
Since user shadow stacks explicitly only support 64-bit mode, the
simplest fix is to fault attempts to do 32-bit rt_sigreturn.
Richard Patel (3):
x86/shstk: ban ia32 sigreturn when shadow stack is enabled
selftests/x86: test shadow stack sigreturn protection
selftests/x86: skip shstk tests where perf_event_open() fails
arch/x86/kernel/signal_32.c | 4 +
.../testing/selftests/x86/test_shadow_stack.c | 120 +++++++++++++++++-
2 files changed, 122 insertions(+), 2 deletions(-)
--
2.52.0