Re: [PATCH] binder: forbid VMA splitting and mremap on binder mmap
From: Carlos Llamas
Date: Wed Sep 23 2026 - 16:47:29 EST
On Sat, Sep 19, 2026 at 09:36:53PM +0000, Hui Peng wrote:
> `binder_vm_ops` does not implement `.may_split` or `.mremap`, and
> `binder_vma_close()` unconditionally calls
> `binder_alloc_vma_close(&proc->alloc)` (which sets `alloc->vma = NULL`).
>
> If userspace calls `munmap()` on a sub-range of the binder mapping (or
> `mremap()` to move/split a sub-range), the VMA is split into two VMAs
> sharing the same `binder_proc`, and `binder_vma_close()` runs on the
> unmapped half and clears `alloc->vma = NULL` while the remaining VMA
> stays mapped in the process's address space, desynchronizing
> `alloc->vma` from the remaining VMA.
>
> Implement `.may_split` and `.mremap` returning `-EINVAL` in
> `binder_vm_ops` and check `vma->vm_start == proc->alloc.vm_start` in
> `binder_vma_close()`.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
This is not correct.
Also, this exact fix has been previously sent here:
https://lore.kernel.org/all/20260901205250.1638304-1-cmllamas@xxxxxxxxxx/
--
Carlos Llamas