Glossary
SMEP and SMAP
CPU features that stop the kernel from executing (SMEP) or accessing (SMAP) user-space memory, breaking the classic ret2usr kernel-exploitation technique.
SMEP (Supervisor Mode Execution Prevention) and SMAP (Supervisor Mode Access Prevention) are x86 CPU features, configured via the CR4 register, that stop privileged (ring 0) code from trusting user-space memory. SMEP faults if the kernel tries to execute a user page; SMAP faults if it tries to read or write one without explicitly toggling a flag.
Together they break ret2usr, where a kernel exploit pointed hijacked kernel execution at an attacker payload mapped in user space. The response is kernel ROP: reuse kernel code and keep all data in kernel memory. Modern kernels also pin CR4 to block the trick of clearing the SMEP bit with a gadget. See ret2usr, SMEP and SMAP.