Fedora Account System
Red Hat Associate
Red Hat Customer
libSvtAv1Enc is built without shadow stack support due to hand written assembly files missing annotations. Therefore, Fedora applications that link against it are lacking protection at runtime. Upstream SVT-AV1 git doesn't have a fix AFAIK. Since the changes are mechanical (annotate function entry points with endbr64 for IBT support and add an ELF note marking CET support), I used an LLM to try to produce a downstream patch (which also applies to upstream git). I'm going to attach it to this bug. It appears to lead to a clean (but untested) scratch build on rawhide. Some background on why this bug is being filed and marked with a "High" severity: We (the glibc team) are planning to enable Shadow Stack protection by default in Fedora 45, and this bug report is a result of early testing. Here is a WIP/draft Fedora System-Wide Change Proposal: https://fedoraproject.org/wiki/Changes/ShadowStack There are some notes in the Documentation section of the change proposal on how to identify and fix smaller issues (such as a stray assembly file without annotations): https://fedoraproject.org/wiki/Changes/ShadowStack#Documentation Reproducible: Always
Created attachment 2137632 [details] test-CET-fix.patch
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle. Changing version to 45.