With Linux 6.6, the mainline kernel finally landed support for Shadow Stack on Intel/AMD CPUs that was originally rolled out as part of Intel's Control-flow Enforcement Technology (CET) for better fending off ROP attacks
While Intel Shadow Stack support has been around since Tiger Lake CPUs as part of Intel's Control-flow Enforcement Technology (CET), finally for the Linux 6.4 kernel is this security feature being enabled with the mainline Linux kernel.
Microsoft may have quietly fixed the Local Security Authority (LSA) is off issue with a recent update to Defender. The company is also pushing out new kernel-mode hardware stack protection.
Control-flow integrity (CFI) refers to techniques which prevent control-flow hijacking attacks. This article describes some compiler/hardware features with a focus on llvm-project implementations. CFI