[PATCH 0/3] x86/shstk: ban ia32 sigreturn

From: Richard Patel

Date: Thu Oct 08 2026 - 16:22:21 EST


User shadow stacks protect only the x64 and x32 rt_sigreturn syscalls.
Calling ia32 rt_sigreturn, which lacks return address validation, is
still possible via `int $0x80`. The bypass also requires the executable
is mapped into low 32-bit address space. (This scenario is basically
impossible to occur in the wild, but it's probably worth fixing
nonetheless.)

Since user shadow stacks explicitly only support 64-bit mode, the
simplest fix is to fault attempts to do 32-bit rt_sigreturn.

Richard Patel (3):
x86/shstk: ban ia32 sigreturn when shadow stack is enabled
selftests/x86: test shadow stack sigreturn protection
selftests/x86: skip shstk tests where perf_event_open() fails

arch/x86/kernel/signal_32.c | 4 +
.../testing/selftests/x86/test_shadow_stack.c | 120 +++++++++++++++++-
2 files changed, 122 insertions(+), 2 deletions(-)

--
2.52.0