[PATCH] exec: snapshot the dentry name before setting task comm
From: Kyle Zeng
Date: Tue Oct 06 2026 - 18:15:28 EST
For an empty execveat() pathname, begin_new_exec() passes a live dentry
name to __set_task_comm(). RCU keeps the name allocation alive, but does
not prevent a concurrent rename from changing an inline name.
__set_task_comm() measures the source before copying it. If a rename
replaces a long inline name with a shorter one in between, the copy can
include stale slab bytes after the new NUL. The subsequent padding starts
at the old length, leaving those bytes in task->comm. An unprivileged
task can observe the suffix through a count-only syscall tracepoint
filter such as COMM ~ "*pattern*".
Take a dentry name snapshot before setting comm and release it afterwards.
The snapshot retries concurrent renames and either copies the inline name
or holds a reference to an immutable external name. This gives both the
tracepoint and the length/copy sequence a stable source while preserving
the selected executable and the existing comm truncation and padding.
Fixes: 543841d18060 ("exec: fix up /proc/pid/comm in the execveat(AT_EMPTY_PATH) case")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: Codex:gpt-6-astra
Signed-off-by: Kyle Zeng <kylebot@xxxxxxxxxx>
---
fs/exec.c | 17 +++++++----------
1 file changed, 7 insertions(+), 10 deletions(-)
diff --git a/fs/exec.c b/fs/exec.c
index 819643408e6d..34cf557a17f7 100644
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1279,19 +1279,16 @@ int begin_new_exec(struct linux_binprm * bprm)
*/
if (bprm->comm_from_dentry) {
struct file *comm_file = bprm_identity_file(bprm);
+ struct name_snapshot name;
/*
- * Hold RCU lock to keep the name from being freed behind our back.
- * Use acquire semantics to make sure the terminating NUL from
- * __d_alloc() is seen.
- *
- * Note, we're deliberately sloppy here. We don't need to care about
- * detecting a concurrent rename and just want a terminated name.
+ * __set_task_comm() measures the name before copying it. Keep
+ * a rename from shortening the name and exposing stale bytes
+ * in the inline name buffer.
*/
- rcu_read_lock();
- __set_task_comm(me, smp_load_acquire(&comm_file->f_path.dentry->d_name.name),
- true);
- rcu_read_unlock();
+ take_dentry_name_snapshot(&name, comm_file->f_path.dentry);
+ __set_task_comm(me, name.name.name, true);
+ release_dentry_name_snapshot(&name);
} else {
__set_task_comm(me, kbasename(bprm->filename), true);
}
base-commit: fd179f8a05be3ccae366b9b96e176b51fbe54aab
--
2.53.0