Bug 2458657 - libgnutls is not compatible with Shadow Stack protection
Summary: libgnutls is not compatible with Shadow Stack protection
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: gnutls
Version: 45
Hardware: x86_64
OS: Linux
unspecified
high
Target Milestone: ---
Assignee: Red Hat Crypto Team
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 2458434
TreeView+ depends on / blocked
 
Reported: 2026-04-15 11:27 UTC by Arjun Shankar
Modified: 2026-08-17 14:33 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:
fedora-admin-xmlrpc: mirror+


Attachments (Terms of Use)

Description Arjun Shankar 2026-04-15 11:27:54 UTC
libgnutls is built without shadow stack support. Therefore, Fedora applications that link against it are lacking protection at runtime.

As far as I can tell, gnutls upstream has started work on it, but due to various reasons including licensing, it has not been completed so far:
https://gitlab.com/gnutls/gnutls/-/work_items/1658
https://gitlab.com/gnutls/gnutls/-/work_items/1043

Some background on why this bug is being filed and marked with a "High" severity:

We (the glibc team) are planning to enable Shadow Stack protection by default in Fedora 45, and this bug report is a result of early testing. Here is a WIP/draft Fedora System-Wide Change Proposal: https://fedoraproject.org/wiki/Changes/ShadowStack

There are some notes in the Documentation section of the change proposal on how to identify and fix smaller issues (such as a stray assembly file without annotations):
https://fedoraproject.org/wiki/Changes/ShadowStack#Documentation
However, in the case of gnutls, looks like upstream is aware of the issue already.

Reproducible: Always

Comment 1 Aoife Moloney 2026-08-17 14:33:39 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.


Note You need to log in before you can comment on or make changes to this bug.