Skip to content

Glossary

Pointer authentication (PAC)

An ARMv8.3 feature that signs pointers with a secret key so a tampered pointer, such as an overwritten return address, fails authentication and faults.

Pointer authentication (PAC) is an AArch64 feature that computes a short cryptographic signature — a pointer authentication code — over a pointer and a context value using a per-process secret key, storing it in the pointer's unused high bits. Instructions such as paciasp sign the link register in a function's prologue and autiasp authenticate it before ret.

Because an attacker who overwrites a saved return address cannot compute a valid signature without the key, authentication fails and the process faults instead of returning to attacker-chosen code. This directly attacks the backward edge that return-oriented programming depends on. It is enabled with -mbranch-protection=pac-ret and pairs with BTI. See PAC and BTI.