Using a separate register to store return address?

Viewed 788

I'm reading about how exploits work, and it seems like a lot of them operate by overwriting the return address on the stack. There's been a lot of effort put into making this more difficult (stack canaries, ASLR, DEP, etc), but it seems to me that it would be easier for hardware producers to add a register, only accessible by the call and ret instructions, that would hold the return address. This way, the return address could not be overwritten by a buffer overflow by definition. Because call and ret are still present and still operate as in today's CPUs (the only difference is where they store the return address), it would seem to me that there wouldn't be too many issues with compatibility. And since you're using a register instead of RAM to access the address, the performance impact would probably be positive (albeit insignificant).

Intel apparently has space to allocate more registers for security purposes, since MPX is being implemented despite needing two extra registers. So why don't they add a special register to store the return address?

1 Answers
Related