Too Subtle to Notice: Investigating Executable Stack Issues in Linux Systems
Hengkai Ye, Hong Hu
Abstract
—Code injection was a favored technique for attackers to exploit buffer overflow vulnerabilities decades ago. Subse-quently, the widespread adoption of lightweight solutions like write-xor-execute (W ⊕ X) effectively mitigated most of these attacks by disallowing writable-and-executable memory. However, we observe multiple concerning cases where software developers accidentally disabled W ⊕ X and reintroduced executable stacks to popular applications. Although each violation has been properly fixed, a lingering question remains: what underlying factors contribute to these recurrent mistakes among developers, even in contemporary software development practices? In this paper, we conduct two investigations to gain a comprehensive understanding of the challenges associated with properly enforcing W ⊕ X in Linux systems. First, we delve into program-hardening tools to assess whether experienced security developers consistently catch the necessary steps to avoid executable stacks. Second, we analyze the enforcement of W ⊕ X on Linux by inspecting the source code of the compilation toolchain, the kernel, and the loader. Our investigation reveals that properly enforcing W ⊕ X on Linux requires close collaboration among multiple components. These tools form a complex chain of trust and dependency to safeguard the program stack. However, developers, including security researchers, may overlook the subtle yet essential .note.GNU-stack section when writing assembly code for various purposes, and inadvertently introduce executable stacks. For example, 11 program-hardening tools implemented as inlined reference monitors (IRM) introduce executable stacks to all “hardened” applications. Based on these findings, we discuss potential exploitation scenarios by attackers and provide suggestions to mitigate this issue.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on19
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Data-Oriented Programming: On the Expressiveness of Non-control Data AttacksHong Hu, Shweta Shinde, Sendroiu Adrian, Zheng Leong Chua et al.S&P 2016 · 420 citations
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
- Ramblr: Making Reassembly Great AgainRuoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry et al.NDSS 2017 · 155 citations
Related papers
- SoK: Take a Deep Step into Linux Kernel Hardening Effectiveness from the Offensive-Defensive PerspectiveYinhao Hu, Pengyu Ding, Zhenpeng Lin, Dongliang Mu et al.NDSS 2026 · 3 citations
- A Generic Technique for Automatically Finding Defense-Aware Code Reuse AttacksEdward J. Schwartz, Cory F. Cohen, Jeffrey Gennari, Stephanie SchwartzCCS 2020 · 8 citations
- NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64Yaohui Chen, Dongli Zhang, Ruowen Wang, Rui Qiao et al.S&P 2017 · 46 citations
- Leakage-Resilient Layout Randomization for Mobile DevicesKjell Braden, Lucas Davi, Christopher Liebchen, Ahmad-Reza Sadeghi et al.NDSS 2016 · 90 citations
- RetSpill: Igniting User-Controlled Data to Burn Away Linux Kernel ProtectionsKyle Zeng, Zhenpeng Lin, Kangjie Lu, Xinyu Xing et al.CCS 2023 · 9 citations
