Crashing Through Defenses: Exploiting Segfaults and Chaining Around Intel CET
Marcos Bajo, Ritvik Goyal, Apostolos Chatzianagnostou, Christian Rossow
Abstract
Code reuse is the predominant attack strategy for exploiting memory corruption vulnerabilities in modern software. In response, Control Flow Integrity (CFI) has been adopted to restrict unintended control-flow transfers and mitigate these attacks. Intel Control-Flow Enforcement Technology (CET) is the most popular CFI implementation in modern x86_64 systems, providing hardware-based protection against conventional code reuse attacks such as ROP and SROP. Although advanced techniques have been proposed to bypass Intel CET, they typically require application-specific features or uncommon programming constructs, limiting their practical applicability. This paper introduces Segmentation Fault Oriented Programming (SFOP), a novel code reuse attack that exploits previously unidentified weaknesses in the interaction between Intel CET and the Linux signal handling subsystem. Unlike other code reuse techniques, SFOP does not require program-specific features, and can reliably exploit any vulnerable application on modern x86_64 Linux with Intel CET enabled. SFOP enables an attacker to execute arbitrarily many function calls with fully controlled arguments, turning a single memory corruption vulnerability into arbitrary code execution. We demonstrate the practical impact of SFOP through real-world exploits, and discuss mitigation strategies to prevent SFOP attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get c927edbb-8658-43be-b332-c4c85052e9bcRelated papers
- Await() a Second: Evading Control Flow Integrity by Hijacking C++ CoroutinesMarcos Bajo, Christian RossowUSENIX Security 2025
- Block Oriented Programming: Automating Data-Only AttacksKyriakos K. Ispoglou, Bader AlBassam, Trent Jaeger, Mathias PayerCCS 2018 · 143 citations
- SpecCFI: Mitigating Spectre Attacks using CFI Informed SpeculationEsmaeil Mohammadian Koruyeh, Shirin Haji Amin Shirazi, Khaled N. Khasawneh, Chengyu Song et al.S&P 2020 · 74 citations
- PLaTypus: Restricting Cross-Module Transitions to Mitigate Code-Reuse AttacksApostolos Chatzianagnostou, Marcos Bajo, Christian RossowS&P 2026
- IMIX: In-Process Memory Isolation EXtensionTommaso Frassetto, Patrick Jauernig, Christopher Liebchen, Ahmad-Reza SadeghiUSENIX Security 2018 · 77 citations
