Re: [PATCH bpf-next v3 3/7] exec: Clear bprm->mm before dropping its reference

From: sun jian

Date: Mon Aug 31 2026 - 23:24:10 EST


On Mon, Aug 31, 2026 at 5:52 PM Anastasios Papagiannis
<tasos.papagiannnis@xxxxxxxxx> wrote:
>
> Once mmput() drops the final reference to bprm->mm, the pointer must no
> longer remain accessible through struct linux_binprm.
>
> The successful exec path and the bprm initialization error path already
> clear bprm->mm when ownership is transferred or released. Do the same in
> free_bprm() before calling mmput().
>
> This is required for eBPF kfuncs where bprm->mm is either NULL or points
> to a live mm_struct to ensure safe access.
>
> Signed-off-by: Anastasios Papagiannis <tasos.papagiannnis@xxxxxxxxx>
> ---
> fs/exec.c | 7 +++++--
> 1 file changed, 5 insertions(+), 2 deletions(-)
>
> diff --git a/fs/exec.c b/fs/exec.c
> index a14f28b15607..4b4d8f0627a7 100644
> --- a/fs/exec.c
> +++ b/fs/exec.c
> @@ -1453,9 +1453,12 @@ void bprm_drop_loader(struct linux_binprm *bprm)
>
> static void free_bprm(struct linux_binprm *bprm)
> {
> - if (bprm->mm) {
> + struct mm_struct *mm = bprm->mm;
> +
> + if (mm) {
> acct_arg_size(bprm, 0);
> - mmput(bprm->mm);
> + bprm->mm = NULL;
> + mmput(mm);
> }
> if (bprm->user_ns)
> put_user_ns(bprm->user_ns);
> --
> 2.55.0
>
>
Reviewed-by: Sun Jian <sun.jian.kdev@xxxxxxxxx>