HIGH Introduced in 6.6
mm ShadowStack Bypass
CVE-2026-68166
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
01Description
In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ... and inject a page with chosen return addresses via UFFDIO_COPY. Update vma_can_userfault() to reject VM_SHADOW_STACK. While on it, also reject VM_SPECIAL so that if a driver would implement vm_uffd_ops, it wouldn't be possible to register special VMAs with userfaultfd. Since VM_SPECIAL includes VM_DONTEXPAND which is set but hugetlb, exclude hugetlb VMAs from the check for VM_SPECIAL.
02KernelScan AI Analysis
Risk summary
A process with userfaultfd access can register shadow stack VMAs, discard pages, and inject pages with attacker-chosen return addresses via UFFDIO_COPY. This defeats hardware CET (Control-flow Enforcement Technology) shadow stack protection, enabling return-oriented programming attacks on systems that rely on CET for control-flow integrity. Any local process with userfaultfd access on CET-capable hardware is affected.
Vulnerability analysis
The kernel's userfaultfd mechanism did not prevent registration of shadow stack memory areas. A process could use this to discard a shadow stack page and replace it with one containing attacker-chosen return addresses, bypassing the hardware protection that prevents return-oriented programming. The corrected code now blocks userfaultfd from handling shadow stacks and other special memory areas, while still permitting it for legitimate large-page uses. Any local, unprivileged process with access to userfaultfd on a system that supports shadow stacks can reach this flaw.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 7.1 | 6.6 | 7.1.6 | 0c26202b157f |
| 6.18 | 6.6 | 6.18.44 | 165613191ad9 |
| 6.12 | 6.6 | 6.12.105 | 495a28d5a100 |
| mainline | 6.6 | 7.2 | 3c58f641e813 |
| 6.6 | 6.6 | 6.6.153 | d974b4b78621 |