KernelScan.io

HIGH Introduced in 6.6

mm ShadowStack Bypass

CVE-2026-68166

CVSS 7.3 / 10.0 KernelScan AI

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

01

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can register on the shadow stack, discard a page ... and inject a page with chosen return addresses via UFFDIO_COPY. Update vma_can_userfault() to reject VM_SHADOW_STACK. While on it, also reject VM_SPECIAL so that if a driver would implement vm_uffd_ops, it wouldn't be possible to register special VMAs with userfaultfd. Since VM_SPECIAL includes VM_DONTEXPAND which is set but hugetlb, exclude hugetlb VMAs from the check for VM_SPECIAL.

02

Engine v0.6.0

Risk summary

A process with userfaultfd access can register shadow stack VMAs, discard pages, and inject pages with attacker-chosen return addresses via UFFDIO_COPY. This defeats hardware CET (Control-flow Enforcement Technology) shadow stack protection, enabling return-oriented programming attacks on systems that rely on CET for control-flow integrity. Any local process with userfaultfd access on CET-capable hardware is affected.

Affectedmm/userfaultfd.c (userfaultfd)

Vulnerability analysis

The kernel's userfaultfd mechanism did not prevent registration of shadow stack memory areas. A process could use this to discard a shadow stack page and replace it with one containing attacker-chosen return addresses, bypassing the hardware protection that prevents return-oriented programming. The corrected code now blocks userfaultfd from handling shadow stacks and other special memory areas, while still permitting it for legitimate large-page uses. Any local, unprivileged process with access to userfaultfd on a system that supports shadow stacks can reach this flaw.

03

BranchIntroducedFixed inPatch commit
7.16.67.1.60c26202b157f
6.186.66.18.44165613191ad9
6.126.66.12.105495a28d5a100
mainline6.67.23c58f641e813
6.66.66.6.153d974b4b78621