Lune

S&P2026顶会

Crashing Through Defenses: Exploiting Segfaults and Chaining Around Intel CET

Marcos Bajo, Ritvik Goyal, Apostolos Chatzianagnostou, Christian Rossow

2026年份

摘要

Code reuse is the predominant attack strategy for exploiting memory corruption vulnerabilities in modern software. In response, Control Flow Integrity (CFI) has been adopted to restrict unintended control-flow transfers and mitigate these attacks. Intel Control-Flow Enforcement Technology (CET) is the most popular CFI implementation in modern x86_64 systems, providing hardware-based protection against conventional code reuse attacks such as ROP and SROP. Although advanced techniques have been proposed to bypass Intel CET, they typically require application-specific features or uncommon programming constructs, limiting their practical applicability. This paper introduces Segmentation Fault Oriented Programming (SFOP), a novel code reuse attack that exploits previously unidentified weaknesses in the interaction between Intel CET and the Linux signal handling subsystem. Unlike other code reuse techniques, SFOP does not require program-specific features, and can reliably exploit any vulnerable application on modern x86_64 Linux with Intel CET enabled. SFOP enables an attacker to execute arbitrarily many function calls with fully controlled arguments, turning a single memory corruption vulnerability into arbitrary code execution. We demonstrate the practical impact of SFOP through real-world exploits, and discuss mitigation strategies to prevent SFOP attacks.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖