
UpdatedAug 8, 2026
cve-2026-43499 — Updated!
PD2229B的43499(ghostlock)可行性研究
GhostLock Exploitation Failure Summary on PD2229 (SM8475, 5.10.233 GKI)
I. Vulnerability and Device Facts
1.1 CVE-2026-43499 (GhostLock) Basic Information
| Item | Value |
|---|---|
| Vulnerability Type | Stack Use-After-Free in the rt_mutex / futex PI path |
| Introduced Version | Linux 2.6.39-rc1 (May 2011, commit 8161239a8bcc) |
| Fixed Version | mainline 7.1 (commit 3bfdc63936dd), stable branches: 6.1.175 / 6.6.140 / 6.12.86 / 6.18.27 / 7.0.4 |
| Prerequisite | CONFIG_FUTEX_PI=y (enabled by default in mainstream kernels) |
| CVSS | 7.8 High |
| Exploit Stability | NebuSec original chain 97%, root in ~5 seconds |
| kernelCTF Bounty | $92,337 USD |
Affected kernel ranges:
- 2.6.39 ≤ Linux < 6.1.175 ✅ Affected
- 6.2 ≤ Linux < 6.6.140 ✅ Affected
- 6.7 ≤ Linux < 6.12.86 ✅ Affected
- 6.13 ≤ Linux < 6.18.27 ✅ Affected
- 6.19 ≤ Linux < 7.0.4 ✅ Affected
- Android GKI 5.10 is in none of the fix branches → PD2229's 5.10.233 is theoretically affected
1.2 PD2229 Device Measurements
| Item | Value |
|---|---|
| SoC | Qualcomm SM8475 (Snapdragon 8 Gen 1 Plus) |
| Kernel Version | 5.10.233-gki-g6e61de9f5b58 #1 SMP PREEMPT (Nov 24 2025) |
| Android Version | 15 (OriginOS 5) |
| Build Date | 2025/11/25 |
| Android Security Patch | 2025/11/01 |
CONFIG_FUTEX_PI | y ✅ |
CONFIG_UNMAP_KERNEL_AT_EL0 | y (KPTI enabled) |
kptr_restrict | enforced |
CONFIG_IO_URING | y ✅ (confirmed via vmlinux symbols, and seccomp does not intercept io_uring_setup) |
II. Ideal Exploit Chain vs Actual PD2229 Progress
2.1 NebuSec Original Chain (successful on x86_64 / Pixel 10)
1. KASLR 绕过 → prefetch timing / PR_SET_MM_MAP auxv
2. UAF 触发 → 三线程 PI 依赖死锁 → FUTEX_CMP_REQUEUE_PI 返回 -EDEADLK
3. 栈回收 → PR_SET_MM_MAP 将 auxv 拷贝到 waiter 栈帧
4. rb_erase 受限写 → 覆写 inet6_protos[IPPROTO_UDP]
5. CEA + ROP → 控制流劫持
6. core_pattern 翻转 → root shell (97% 成功率)
2.2 Actual PD2229 Progress by Stage
| Stage | Status | Description |
|---|---|---|
| 1. KASLR Bypass | ✅ Implemented | perf_event_open + callchain sampling side channel (same method as the OPPO Find X6 Pro 5.15.149 adaptation) |
| 2. UAF Trigger | ✅ Implemented | Three-thread PI deadlock succeeds, FUTEX_CMP_REQUEUE_PI returns -EDEADLK |
| 3. Stack Reclaim Primitive | ❌ Architectural failure | Stack frames of all known syscalls do not overlap the waiter (see Section III) |
| 4. rb_erase Constrained Write | ❌ Blocked | Prerequisite not met |
| 5. inet6_protos Overwrite | ❌ Not started | Depends on stage 4 |
| 6. ROP / Control Flow Hijack | ❌ Not started | Depends on stage 5 |
| 7. Root Shell | ❌ Not started | Depends on stage 6 |
III. Stack Reclaim Primitive Exhaustive Search Results (PD2229 Measured)
3.1 Key Stack Frame Layout Calculations
futex 路径总深度:
__arm64_sys_futex 0x90
+ do_futex 0xc0
+ futex_wait_requeue_pi 0x1b0
= 0x300
waiter 位置 = SYS_SP - 0x300 + 0x20 = SYS_SP - 0x2e0
pselect 路径:
core_sys_select 栈帧 0x1c0, stack_fds 在 sp+0x50
覆盖区间: SYS_SP - 0x1c0 + 0x50 = SYS_SP - 0x170 起
与 waiter (SYS_SP - 0x2e0) 差距 0x170 (368 字节) → 不重叠
3.2 17 Stack Write Methods Attempted
| # | Method | Syscall | PD2229 Result | Core Failure Reason |
|---|---|---|---|---|
| 1 | stamp_prctl | PR_SET_MM_MAP | ❌ EPERM | Android hard block |
| 2 | stamp_pselect | pselect6 (NFDS=320) | ❌ No overlap | waiter is 120B below fd_set |
| 3 | stamp_pselect | pselect6 (NFDS>336) | ❌ Heap allocation | kvmalloc path |
| 4 | stamp_socket | MCAST_JOIN_SOURCE_GROUP | ❌ Insufficient overwrite | Only writes the lock field |
| 5 | stamp_sendmsg | sendmsg | ❌ 80B from waiter | Stack frame 0x90 too shallow |
| 6 | stamp_sendmmsg | sendmmsg | ❌ 112B from waiter | Insufficient stack frame |
| 7 | stamp_recvmmsg | recvmmsg | ❌ Zeroes task/lock | 0x1d0 stack frame corrupts key pointers |
| 8 | stamp_process_vm | process_vm_writev | ❌ No overlap | Child thread stack allocated separately |
| 9 | stamp_keyctl | KEYCTL_INSTANTIATE_IOV | ❌ EOPNOTSUPP | Syscall unsupported + stack frame 0x40 |
| 10 | stamp_tcp | TCP_ZEROCOPY_RECEIVE | ❌ Insufficient stack frame | Estimated depth not enough |
| 11 | stamp_futex | FUTEX_CMP_REQUEUE_PI recursion | ❌ Logically infeasible | Corrupts the UAF window |
| 12 | binder ioctl | BINDER_WRITE_READ | ❌ EACCES | shell lacks /dev/binder permission |
| 13 | poll | poll | ❌ Heap allocation | pollfd is on the heap |
| 14 | epoll_wait | epoll_wait | ❌ Frame too shallow | Stack frame 0xE0 |
| 15 | sched_setattr | sched_setattr | ❌ Insufficient depth | Stack frame 0xb0 |
| 16 | timerfd_settime | timerfd_settime | ❌ No stack copy | No large stack buffer |
| 17 | io_uring_register | IORING_REGISTER_* | ❌ Double failure | ①Stack frame is only 0xF0, and the copy_from_user target is fixed at sp+0x8 (424 bytes away from the waiter's sp+0x1D0); ②although io_uring_setup is not intercepted by seccomp (returns EFAULT instead of ENOSYS), the stack layout does not match |
17/17 all failed.
3.3 Root Cause of Failure
The stack layout produced by PD2229's SM8475 5.10 GKI compiler (PGO + LTO + BOLT) causes core_sys_select's stack_fds and futex_wait_requeue_pi's rt_mutex_waiter to be architecturally non-overlapping. This is an objective fact determined by the compiler, not an exploit technique issue.
The JoinChang repository explicitly states: "The pselect stack overlay only works when the freed rt_mutex_waiter lands within the user-controllable region of the stack_fds buffer" — PD2229 does not satisfy this condition.
IV. Public Reference Repository Comparative Analysis
NebuSec/CyberMeowfia — Original Exploit Framework
- Repository: https://github.com/NebuSec/CyberMeowfia
- Target: x86_64 Linux / Pixel 10 (6.x GKI)
- Stack Reclaim:
PR_SET_MM_MAPcopies auxv to the kernel stack - Success Rate: 97%, root [shell] in ~5 seconds
- PD2229 Applicability: ❌
PR_SET_MM_MAPis blocked by EPERM on Android
JoinChang/ghostlock-oneplus — OnePlus locked-BL jailbreak
- Repository: https://github.com/JoinChang/ghostlock-oneplus
- Verified Devices:
- OnePlus Ace 6T (PLR110, SM8845) — 6.12.38 GKI ✅
- OnePlus 15 (PLK110, SM8845) — 6.12.23 GKI ✅
- Technical Highlights:
- Offset auto-extraction: kallsyms (28) + BTF (57) + derived (9) + constants (12) = 103/103
- pselect stack overwrite, SP diff = -64
PSELECT_SHIFT = -2- Exploit chain: futex UAF → forge waiter → pselect controls the stack → rb_erase constrained write → selinux_state.enforcing=0 → overwrite cred with init_cred
- Explicitly declared infeasible: "Not Feasible (stack layout incompatible)" — only applies to kernels where pselect stack_fds overlaps the waiter
- PD2229 Applicability: ❌ Kernel generation mismatch (6.12 vs 5.10), and stack layouts do not overlap
p2p3p/GhostLock-for-OnePlus — Complete OnePlus 6.12 Exploit
- Repository: https://github.com/p2p3p/GhostLock-for-OnePlus
- Verified: OnePlus Ace 6T (SM8845, 6.12.38) ✅
- PD2229 Applicability: ❌ Same as JoinChang, kernel generation mismatch
YuKongA/ghostlock-oplus — OPPO Find N5/X8
- Repository: https://github.com/YuKongA/ghostlock-oplus
- Kernel: 6.6.118 GKI
- PD2229 Applicability: ❌ Kernel generation mismatch
OPPO Find X6 Pro (PGEM10) Adaptation — 5.15.149
- Device: SM8550, 5.15.149-android13, Android 15
- Progress: ✅ KASLR bypass (perf_event_open + callchain sampling); later stages not publicly disclosed as a complete exploit
- Significance: Proves KASLR bypass is feasible on 5.15 GKI, but the stack reclaim stage has not been publicly verified