Glossary
Control-flow integrity (CFI)
A family of mitigations that check at runtime that indirect calls, jumps and returns go only to targets the program could legitimately reach.
Control-flow integrity (CFI) restricts where a program's indirect control transfers may go. Forward-edge CFI checks indirect calls and jumps, for example with Clang's type-based -fsanitize=cfi, Microsoft Control Flow Guard, Intel IBT or Arm BTI. Backward-edge CFI checks returns, for example with a hardware shadow stack or Arm pointer authentication.
CFI targets code-reuse techniques that survive non-executable memory. It narrows rather than eliminates attacker options: coarse schemes allow any valid target, and data-only attacks are out of scope. See control-flow integrity.