Hi! As it was brought up recently in #1113864, it seems like we are lacking support from glibc (and Linux) for full CET coverage on amd64. On the kernel there seems to still be missing support for IBT, which means glibc cannot add support to enable it yet, although it has scaffolding for it (tunables and ELF markings etc). But at least both have support for shadow stacks. I think it would be nice to enable CET support, via glibc's configure --enable-cet=permissive option on amd64, so that we can start to exercise this. AFAIUI --enable-cet might currently be too strict, and could refuse to load shared objects that have not yet been marked as supporting CET (shadow stacks and/or IBT), such as packages not using dpkg-buildflags, or for projects with source in assembler that have not been marked with the appropriate section. I think other distributions pass --enable-cet=permissive as well, and I think previously they were passing --enable-cet and had to either revert that due to breakage or switch to --enable-cet=permissive. Checking now Fedora for example I see this: <https://src.fedoraproject.org/rpms/glibc/blob/rawhide/f/glibc.spec#_1412> Thanks, Guillem
Hi, Reading the report, this feature was announced in the Trixie release notes. https://www.debian.org/releases/stable/release-notes/whats-new.html#hardening-against-rop-and-cop-jop-attacks-on-amd64-and-arm64 You may want to consider a backport to Trixie. I was checking that enable-cet could cause plugins or libraries loaded with dlopen to fail, while enable-cet=permissive deactivates CET while dlopen gets executed. As per other distros, checking provided Fedora link and SUSE, both seem to set enable-cet in their strict version (probably after they have rebuilt the archive with permissive option). https://build.opensuse.org/projects/openSUSE:Factory/packages/glibc/files/glibc.spec?expand=1 Héctor Orón -.. . -... .. .- -. -.. . ...- . .-.. --- .--. . .-.
Hi, Unfortunately, configuring glibc with --enable-cet=permissive causes the upstream tst-shstk-legacy-1g test to fail, at least on my laptop (Zen 3 based). This seems similar to this upstream bug, although without using a specific -march= option: https://sourceware.org/bugzilla/show_bug.cgi?id=31877 This needs a bit more investigation to understand why this test fails. Regards Aurelien
What is the status for Forky? What is blocking this? Other distributions appear to have it enabled. Regards Stephan
This is still not enabled. As noted earlier in this bug report, enabling CET support causes one of the corresponding tests to fail. It is not clear why it fails, if it is due to the Debian toolchain and what are the consequences. It has been reported upstream: https://sourceware.org/bugzilla/show_bug.cgi?id=31877 Unfortunately I got not time to investigate further, between handling the new upstream version and all the CVE issue to backport. I only know it is still reproducible with the current version in unstable. Regards Aurelien
In Ubuntu 26.04, the fwupdmgr tool shows this as active and the binaries in /usr/bin have the corresponding flags IBT and SHSTK (checked with readelf). https://bits.debian.org/2025/08/trixie-released.html On Trixie, readelf does not show the flags in most binaries, even though according to the release notes, it should already be enabled in Trixie. What is the difference between Ubuntu and Debian? Are the failing tests specific to Debian? How can one contribute to fix this for Forky? Regards
Hi, This is not the live version of the release notes, which have been fixed: https://www.debian.org/releases/trixie/release-notes/ It is not enabled, that is exactly the purpose of this bug. This is an upstream test that is failing, the issue has been reported here: https://sourceware.org/bugzilla/show_bug.cgi?id=31877 The author of the test explained it was a kernel or CPU bug, the latter being almost impossible as the issue is reproducible on different Intel and AMD CPUs. Ubuntu decided to just ignore the test. At the end, I spend some time debugging that last week-end, and I believe this is a buggy test. I posted a patch, which is under review, let's s see if I am right. If so, we can enable the feature for glibc 2.44 which should end up in Forky. Regards Aurelien
Hello, Bug #1114518 in glibc reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/glibc-team/glibc/-/commit/33891c081a43795bb9f4467a5410880c3de9d121 ------------------------------------------------------------------------ debian/rules.d/build.mk: configure with --enable-cet=permissive when dpkg-buildflags has -fcf-protection. Closes: #1114518. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1114518
We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1114518@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated glibc package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 20 Sep 2026 15:39:36 +0200
Source: glibc
Architecture: source
Version: 2.44-2
Distribution: experimental
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Closes: 1114518
Changes:
glibc (2.44-2) experimental; urgency=medium
.
[ Samuel Thibault ]
* debian/testsuite-xfail-debian.mk: Update hurd results.
* debian/patches/hurd-i386/git-tst-backtrace.diff: Fix tst-backtrace[56].
.
[ Aurelien Jarno ]
* debian/patches/git-updates.diff: update from upstream stable branch:
- Do not load cache extensions from an old-format ld.so.cache
- Drop nonnull attribute for fchmodat, faccessat, fchownat, openat,
openat2's path argument
- Fix tst-shstk-legacy-1{f,g} with a toolchain defaulting to --as-needed
* debian/rules.d/build.mk: configure with --enable-cet=permissive when
dpkg-buildflags has -fcf-protection. Closes: #1114518.
Checksums-Sha1:
a44b369a8dbe331ce8e9cc908758a4fecd6b3bf9 8571 glibc_2.44-2.dsc
b67204a7673e5de85e4ad2b1381cd4b17c4962f3 418328 glibc_2.44-2.debian.tar.xz
cc48239bcf8a823c638998b9a651b3a87c9c0033 9473 glibc_2.44-2_source.buildinfo
Checksums-Sha256:
ec053bac00a9dade9d04a59ec437f8a94562a7cfb29755d03189b808195072aa 8571 glibc_2.44-2.dsc
c6fcd8bf438495b3773b5c82d6a0996aa79c85c70fd839518413f621da736537 418328 glibc_2.44-2.debian.tar.xz
1d87bf80e284d3bec9712d62568d5f2051b8bbd18f9aba47d722a030a95104aa 9473 glibc_2.44-2_source.buildinfo
Files:
75cf4e4d2a1a22ed242c4c56a10234cf 8571 libs required glibc_2.44-2.dsc
c1b7fcf94ac0c9c286247575585bf70a 418328 libs required glibc_2.44-2.debian.tar.xz
dbbbf6d44d71074e708fc9c7a3d682c2 9473 libs required glibc_2.44-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmqv5QEACgkQE4jA+Jno
M2uExQ/+O2TYwDhoL0rXLLlpgv8B5UdbUkEefntZPz1m4aXTkjyRHN56F9elOKoJ
Xo1Co50xaPmLQnZMfamkrdX/5SM2/XFigZvgb3/f5xJuwnYADmzjUKRhWDljBcqY
8IPhvVJz2U3yxwS4jHG+0ihjGwmKeEo5MX1ORBzNvx0dqnMXWU/eoxv+IDAuN8SQ
VXEwP6thEQWMcVn+YrskpM7iHjTbYNfb0eq1cep49k9RHs3omJYvgjFy5RECZXFw
OUg7FEfPV9Futr12LVlm8+7PkLxqI4C9ixmzMy/JUXTQS1X+ysHr5nw091iXW3kH
xUDPH4TjQjePKapxrCtn4L4tdOQ5ssQhXjKzuNUqhMb/2AacXJeuOCde1WuzpkXG
qZhkL1Z+1pDbJa8/DlgeLhAjgZVJeAZ1WkEgNKUUgckO00jqPPa0lumufqJDqNtE
dyJXUUdAXqS3hp31gvEwXF6/9CiPM2QWnHjReO1y7JCoILaI4rNHvaYLupl/dwre
Oa8YqMLz5VIh97IMidaE9gvfp7ZFBLVvUKiv4feLQu+lpuEsWZ91rS2zRvbO4QMI
77r5UYLSRLEQh3nXuxJijqbKVyUUwLO0Qa2sRdrMq+YmXJyocgkSKqRBAAGxDQDt
ZfXxnzP+oWgStzkeM7RyDrt/jsUGc+k/BCCF9NAvZdvxM1mnrwU=
=jVvV
-----END PGP SIGNATURE-----