
Proof-of-concept exploit chain for CVE-2026-43499 targeting OPPO MT6835 Android devices, with preload payload, build system, and analysis notes for defensive research.
GhostLock: Linux Kernel futex PI Use-After-Free vulnerability, CVE-2026-43499. Attackers exploit PI-futex dependency loops to trigger a race condition, achieving local privilege escalation on kernels with
CONFIG_FUTEX_PI=y.Target: OPPO PLS120 (OP5E1C) — Android 17, kernel
5.15.180-android13-8-o-g7b9cfca06464Analysis Environment: Ubuntu 24.04 x86_64 + Android NDK r29 (clang 21.0.0, API 35)
Source Repo: NebuSec/CyberMeowfia — IonStack/CVE-2026-43499
本项目研究在 OPPO PLS120 (OP5E1C) 设备上利用 GhostLock (CVE-2026-43499) 获取 root 权限的可行性。通过系统性地验证所有已知的 KASLR 泄露路径,确认该设备的安全加固组合构成了不可绕过的防护链。
| 阶段 | 状态 | 说明 |
|---|---|---|
| 阶段一:boot.img 分析 & 符号提取 | ✅ 完成 | 从 OTA 包提取 boot.img → vmlinux-to-elf 重建符号表 (159,668 个符号) |
| 阶段二:preload.so 编译 | ✅ 完成 | Android NDK r29 交叉编译,强制实时写盘日志机制 |
| 阶段三:故障诊断与迭代修复 | 🔄 进行中 | 已修复 MM_STRUCT_SZ、MTE 支持、SLIDE 跳过逻辑 |
OPPO PLS120 的安全加固全面封锁了 exploit 链条:
| 加固项 | 影响 |
|---|---|
CONFIG_SLAB_FREELIST_HARDENED=y | 阻止 KernelSnitch slab 碰撞 |
CONFIG_KASAN_HW_TAGS=y (MTE) | 地址标签增加 bruteforce 复杂度 |
CONFIG_CFI_CLANG=y | 控制流完整性 |
| SELinux shell 域策略 | 阻止 perf_event_open + /proc/kallsyms |
CONFIG_CHECKPOINT_RESTORE=n | 阻止 PR_SET_MM_MAP 路径 |
| wchan 修复 backport | 阻止 /proc/<pid>/stat 泄露内核 VA |
| 方案 | 状态 | 原因 |
|---|---|---|
| perf_event_open callchain | ❌ | EACCES (SELinux shell 域封锁) |
| /proc/kallsyms | ❌ | EACCES (kptr_restrict + SELinux) |
| wchan (/proc/<pid>/stat field 35) | ❌ | 内核已应用 v5.16 修复 (返回 1 而非内核 VA) |
| SLIDE 侧信道 (boot_id 覆写) | ❌ | nfulnl 模块不可加载 |
| PR_SET_MM_MAP 栈回收 | ❌ | CONFIG_CHECKPOINT_RESTORE=n |
| KernelSnitch (futex hash timing) | ⚠️ 偶发成功 | 大.LITTLE 时序噪声影响稳定性 |
SLIDE_MAX_ATTEMPTS=1 跳过 SLIDE 死循环!route_signal 立即 break,允许 24 次重试This project researches the feasibility of exploiting GhostLock (CVE-2026-43499) for root privilege escalation on an OPPO PLS120 (OP5E1C) device. After systematically testing all known KASLR leak paths, the device's security hardening configuration forms an unbypassable defense chain against this exploit.
| Phase | Status | Description |
|---|---|---|
| Phase 1: boot.img Analysis | ✅ Complete | Extracted boot.img from OTA → vmlinux-to-elf symbol reconstruction (159,668 symbols) |
| Phase 2: preload.so Build | ✅ Complete | Cross-compiled with Android NDK r29, forced real-time disk logging |
| Phase 3: Diagnosis & Iteration | 🔄 In Progress | Fixed MM_STRUCT_SZ, MTE support, SLIDE bypass logic |
OPPO PLS120 blocks the exploit chain at multiple layers:
| Hardening Feature | Impact |
|---|---|
CONFIG_SLAB_FREELIST_HARDENED=y | Blocks KernelSnitch slab collision |
CONFIG_KASAN_HW_TAGS=y (MTE) | Address tags increase bruteforce complexity |
CONFIG_CFI_CLANG=y | Control Flow Integrity |
| SELinux shell domain policy | Blocks perf_event_open + /proc/kallsyms |
CONFIG_CHECKPOINT_RESTORE=n | Blocks PR_SET_MM_MAP path |
| wchan fix backport | Blocks /proc/<pid>/stat kernel VA leak |
| Method | Status | Reason |
|---|---|---|
| perf_event_open callchain | ❌ | EACCES (SELinux shell domain) |
| /proc/kallsyms | ❌ | EACCES (kptr_restrict + SELinux) |
| wchan (/proc/<pid>/stat field 35) | ❌ | Kernel has v5.16 fix backport (returns 1 instead of kernel VA) |
| SLIDE side-channel (boot_id overwrite) | ❌ | nfulnl module not loadable |
| PR_SET_MM_MAP stack reclaim | ❌ | CONFIG_CHECKPOINT_RESTORE=n |
| KernelSnitch (futex hash timing) | ⚠️ Intermittent | big.LITTLE timing noise affects stability |
SLIDE_MAX_ATTEMPTS=1!route_signal early break, allows 24 retries/home/ubuntu/CyberMeowfia/
├── devices/ # Target device artifacts (OTA zip, config.gz, etc.)
├── work_bootimg/ # boot.img analysis output
│ └── oppo/ # OPPO-specific kernel data
│ ├── kernel.dec # Decompressed ARM64 Image (47MB)
│ ├── vmlinux_extracted.elf # Reconstructed vmlinux with symbols (159,668)
│ ├── kallsyms_oppo.txt # Full symbol table
│ └── kernel_config_oppo # Kernel .config (189KB)
├── IonStack/CVE-2026-43499/exploit/ # Exploit source code
│ ├── src/ # Source files (slide.c, fops.c, main.c, etc.)
│ │ ├── kernelsnitch/ # KernelSnitch futex hash timing module
│ │ └── targets/
│ │ └── oppo-pls120-BP2A.250605.015/ # OPPO-specific target configuration
│ └── build/ # Compiled binaries
├── unpack_bootimg.py # Python boot.img unpacker (v3/v4)
├── report.md # Phase 1 analysis report (Chinese)
├── GhostLock_CVE202643499_OPPO_PLS120_研究报告.md # Full research report (Chinese, 620 lines)
└── CVE202643499.txt # Research plan document
| File | Description |
|---|---|
report.md | Phase 1 analysis: boot.img unpacking, vmlinux extraction, offset validation |
GhostLock_CVE202643499_OPPO_PLS120_研究报告.md | Full research report: complete process, all iterations, failure analysis, conclusions (620 lines) |
Located at IonStack/CVE-2026-43499/exploit/src/targets/oppo-pls120-BP2A.250605.015/target.h:
| Parameter | Value |
|---|---|
KIMAGE_TEXT_BASE | 0xffffffc008000000 |
MM_STRUCT_SZ | 0x3e8 (1000 bytes, verified from mm_cache_init) |
KERNELSNITCH_MTE_ENABLED | 1 (MTE address tag search enabled) |
KSNITCH_COLLISIONS | 2 (big.LITTLE tolerance) |
KERNELSNITCH_MAX_MISMATCH | 1 (timing noise tolerance) |
SLIDE_MAX_ATTEMPTS | 1 (nfulnl unavailable, skip to FOPS path) |
KERNEL_PAGE_SETUP_ATTEMPTS | 6 |
SLIDE_KERNEL_PAGE_SETUP_ATTEMPTS | 12 |
FOPS_KERNEL_PAGE_SETUP_ATTEMPTS | 72 |
# Cross-compilation for ARM64 Android
# Requires Android NDK r29 installed at /home/ubuntu/android-ndk-cache/android-ndk-r29/
# Build preload.so for OPPO PLS120
cd IonStack/CVE-2026-43499/exploit
export ANDROID_NDK_HOME=/home/ubuntu/android-ndk-cache/android-ndk-r29
make PROJECT=oppo-pls120-BP2A.250605.015 preload
# Build for default Pixel target
make PROJECT=blazer-CP2A.260605.012 preload
| Resource | Link |
|---|---|
| GhostLock Vulnerability Detail | Mallory AI |
| IonStack Part II Writeup | NebuSec AI |
| KernelSnitch Heap KASLR Leak | Lukas Maar |
| CVE-2026-43499 Source | GitHub NebuSec |