Fedora 45 Plans to Include Shadow Stack Protection

In the Fedora Linux 45 release, scheduled for fall 2026, the use of a shadow stack is planned to be enabled by default on x86_64 systems. This feature aims to block exploits that overwrite function return addresses in the event of a stack buffer overflow. The protection is intended to be activated for all applications and libraries compiled with gcc (C, C++), clang (C, C++), and rustc (Rust). This plan has not yet been approved by the FESCo (Fedora Engineering Steering Committee), which is responsible for the technical aspects of Fedora Linux development. The initiator for including the shadow stack in Fedora is Arjun Shankar from Red Hat, who manages the glibc packages in Fedora and RHEL.

The protection is implemented using the hardware capabilities of processors and is based on the fact that after control is passed to a function, return addresses are stored by the processor not only in the regular stack but also in a separate 'shadow' stack, which cannot be altered directly. Before exiting a function, the return address is extracted from the shadow stack and verified against the return address in the main stack. A mismatch in these addresses leads to an exception being raised, blocking situations where an exploit has managed to overwrite the address in the main stack. The shadow stack mechanism is supported starting from the 11th generation of Intel processors ('Tiger Lake' and 'Rocket Lake') and the Zen3 microarchitecture in AMD processors.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster