Glossary
Return-oriented programming (ROP)
A code-reuse technique that chains short existing instruction sequences ending in return instructions, used to work around non-executable memory.
Return-oriented programming (ROP) is a code-reuse technique. Instead of injecting new code, which non-executable memory prevents, it redirects execution through a series of short instruction sequences that already exist in the program or its libraries, each ending in a return instruction. Chained together, these fragments can perform arbitrary computation. Related techniques reuse jump- or call-terminated fragments.
For defenders, ROP explains why several mitigations exist: ASLR and PIE hide where the fragments are, and shadow stacks, pointer authentication and control-flow integrity prevent returns and indirect branches from going to unintended places. See control-flow integrity.