Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
ghost-hoock — GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge. | Kitploit
أدوات/GitHubGitHub/genksome/ghost-hoock
Android SecurityPrivilege EscalationMemory ForensicsVulnerability AnalysisExploitationMobile SecurityPapers & ResearchPayload DevelopmentBinary Exploitation
GitHubgenksome/ghost-hoock

ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

451منذ 20 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
عرض المستودع
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

ghost-hoock

A minimal fork of GhostLock that keeps only one primitive: turning off SELinux via CVE-2026-43499 (futex PI UAF).

ghost-hoock running on Samsung A17

kernel device cve license platform


Table of contents

  • What is this
  • How it works
  • What was kept from the original
  • What was removed
  • Building
  • Running
  • Requirements
  • Limitations and risks
  • Project layout
  • License
  • Credits
  • Links

What is this

ghost-hoock is a stripped-down fork of the GhostLock exploit by Mobile Hacking Lab, reduced to a single primitive:

One constrained write via futex PI UAF -> selinux_enforcing = 0.

No root, no cred overwrite, no rwforge channel, no UMH, no configfs. Just the minimum needed to flip SELinux into permissive mode on the vulnerable kernel.

Example output on a Samsung Galaxy A17 (SM-A175F, BZA5):


[] kernel: 6.12.23-android16-5-abA175FXXS5BZD2-4k
[+] offsets matched: 6.12.23-android16-5-abA175FXXS5BZD2-4k
[] init_cred image=ffffffc082512b08 alias=ffffff8002512b08
[+] startup context pid=10331 uid=2000 euid=2000 gid=2000 egid=2000 attr=u:r:shell:s0 enforce=1
[+] startup limits pid=10331 NoNewPrivs=0 Seccomp=0 Seccomp_filters=0
[+] build config pid=10331 label=ghost-hoock
[] p0 kernel_phys_load=0000000040000000 delta=0000000000000000 core=0
[] target selinux_enforcing=ffffff800277e560
[] W1 attempt 1/20
[] === W1: SELinux === target=0xffffff800277e560 mode=1
[] prepare_kernel_page ok attempt=1
[] pselect route setup simple=0 shift=0 page=ffffff806c4f0000 fake_lock=ffffff806c4f0000 ...
[] pselect returned ret=6 errno=0 calls=1 success=1 delay=0
[] pselect route done calls=1 success=1 step=0 errno=0
[+] SELinux DISABLED (attempt 1)

Then:

$ getenforce
Permissive

getenforce returns Permissive


How it works

The exploit targets CVE-2026-43499 — a use-after-free in the Linux kernel's futex PI (Priority Inheritance) rt_mutex chain. The chain in ghost-hoock is four steps:

1. KernelSnitch mm_struct leak

Timing side-channel against the kernel's futex hash table. We hammer FUTEX_WAKE_PRIVATE on a set of user-space futexes, measure rdtsc deltas, and correlate hash-bucket collisions. This recovers the address of our own mm_struct — the base of the spray page we later need.

This is the KernelSnitch technique, taken verbatim from the original exploit.

2. Heap spray

We allocate a large order-3 slab page, then lay it out with the fake-object layout used by the PI route:

OffsetObjectPurpose
0x0E80fake_lockFake rt_mutex
0x0F80fake_fopsFake file_operations table
0x1180fake_w0Fake rt_mutex_waiter used as target tree
0x1240fake_rightFake rb-tree right node — this is where the write value comes from
0x1260fake_leftFake rb-tree left node
0x1280fake_taskFake task_struct

The whole page is sent through an AF_UNIX socket as SKB_SEND_SIZE = 2 * ORDER3_SIZE of sendmsg, so the skb data lands on our leaked page. Then we free it in a controlled order so that our page ends up on a per-cpu partial slab we can reclaim.

3. PI route

Three threads:

  • waiter — enters FUTEX_WAIT_REQUEUE_PI on f_wait, targeting f_pi_target.
  • owner — holds FUTEX_LOCK_PI on f_pi_target and then on f_pi_chain.
  • consumer — spins calling sched_setattr(tid, SCHED_BATCH, nice=19) on the waiter's TID, which triggers rt_mutex_setprio() and forces the kernel to walk the fake PI tree.

A fourth call from the main thread — FUTEX_CMP_REQUEUE_PI(1, f_pi_target) — kicks off the requeue. Inside the kernel, rb_erase() runs against our fake tree.

4. pselect constrained write

pselect() / select() copies the user's fd_set into kernel stack and later walks it. We arrange the fd_set bitmaps so that the words the kernel treats as rb-tree pointers land on fake_right and its parent — and the resulting rb_set_parent(child, parent) becomes:


*(uint64_t *)target = value | color

For mode = 1 (Write 1), target = selinux_enforcing and value = base + 0x100, which encodes as byte0 = 0, byte1 = 1. The kernel writes 0 to selinux_enforcing[0] — SELinux is now permissive.

ret = 6 (instead of the default 9) confirms the write landed: the consumer hit the target during select(), waking it early.


What was kept from the original

This is a fork of mobilehackinglab/ghostlock-a17 (MIT). The following is taken 1:1 from the upstream exploit:

ComponentFileNotes
KernelSnitchsrc/kernelsnitch/*mm_struct leak via futex hash timing
Heap spraysrc/spray.cfake-object layout, prepare_skb_payload, prepare_kernel_page
PI route + pselectsrc/route.cprepare_pselect_fdsets, do_pselect_fake_lock_route, consumer_thread, waiter_thread, owner_thread
BZA5 offsetsinclude/offsets_bza5.hSymbol table extracted from 6.12.23-android16-5-abA175FXXS5BZD2-4k
BZA5 target headerinclude/target.hAddress layout, payload offsets (W1-subset only)
Runtime struct offsetsinclude/runtime_struct_offsets.h_RSO() macros for task_struct fields

Auxiliary code (pr_* macros, SYSCHK, pin_to_core, set_limit, set_unbuffer) is also kept as-is from the original.


What was removed

The original GhostLock achieves full root on the A17: it installs a rwforge physical R/W channel, patches cred / real_cred, runs a UMH helper with init creds, captures logs, and more. In ghost-hoock, everything past the first constrained write is gone.

Removed fileWhy it existed in the original
rwforge_a17.cMarching-forger physical R/W channel via pipe_buffers
pipe_physrw.c, pipe_reclaim.cPipe-buffer reclaim -> arbitrary kernel read/write
root.ccred / real_cred overwrite, su install, SELinux SID patching
umh_root.c, wq_umh_root() (in main.c)Running an init-creds helper from a forged kernel workqueue item
slide.cKASLR leak via boot_id oracle — not needed on BZA5, KASLR is off
miniadb.cBootstrap via ADB TCP
try_cfi_stage() (in fops.c)CFI-friendly configfs stage used to bootstrap the root path
run_rwforge(), run_bootid_oracle(), rwforge_root_and_capture()The whole root pipeline
install_embedded_su(), install_embedded_wallpaper()Root-install helpers
Write 2 (cred), patch_cred_*, patch_task_seccompPost-W1 credential takeover
تنزيل الأداة