
Android root tool for Samsung Galaxy S25 Ultra (SM-S938B) that chains DirtyFrag CVE-2026-43284 and CVE-2026-43499 to gain root automatically at boot via KernelSU.
A fork of diabl0w/DFRoot, specifically ported for the Samsung Galaxy S25 Ultra (SM-S938B / pa3q), with the UI and runtime output entirely in Chinese.
Two chains, one interface:
Method Vulnerability Characteristics Fast Channel DirtyFrag (CVE-2026-43284) The upstream DFRoot chain, seconds to tens of seconds Manual CVE-2026-43499 Probabilistic, three-tier ladder, up to a dozen-plus minutes Default "Auto": run the fast channel first, and if it fails, automatically fall through to the manual method.
In one sentence: automatically gain root on boot. Each boot first tries the fast channel for a few seconds; if that fails, it automatically falls through to the manual chain, retrying in three tiers following "fast → steady → patient".
After gaining root, it also automatically runs two cmd connectivity commands (to remove ads from Samsung's "Package Installer"), with the commands, output, and exit codes all printed to the UI log — see Section 5, "Installer Ad Settings". Starting with v1.8, these two commands are written as a KernelSU boot script, so from then on KernelSU itself executes them as root on every boot, without opening the app or any authorization prompt.
Cannot run program "su": error=2, No such file or directory:
In v1.8, to avoid an extra reboot, the --soft-reboot passed to ksud was removed; however, KernelSU's su is precisely what the kernel module mounts to /system/bin/su only during the post-fs-data stage, and ksud's late-load only runs the stages late-load / post-mount / service / boot-completed (KernelSU source userspace/ksud/src/late_load.rs) — without rebooting the framework, this mount point will never appear during the current boot, and su -c … in the app will inevitably fail with error=2. These two problems share the same root cause;KsudChannel) — the APK now carries an extra copy of ksud (libksud.so, placed in jniLibs/arm64-v8a/, installed into nativeLibraryDir, which the App can directly execve), using libksud.so debug su to open a root shell and writing commands to its stdin. Privilege escalation goes through the kernel's ioctl(KSU_IOCTL_GRANT_ROOT), without depending on /system/bin/su, without an authorization prompt, and without rebooting the system framework;* root channel: helper=…, ksud=available, su=…, so it's obvious at a glance where it's stuck;su, /data/adb/ksu/bin, /debug_ramdisk, /data/adb/magisk, /data/adb/ap/bin are added to PATH, and SU_PATHS is expanded to 8 entries (some KernelSU variants only place su in these directories).--soft-reboot is no longer passed to ksud. Previously this parameter caused ksud to reboot the system framework once after installation — what the user saw was "it rebooted itself again after boot"; worse, this reboot would interrupt the app process along with the "Installer Ad Settings" it was running;su to run it at boot time (at that point KernelSU isn't ready yet, and on real devices it failed on every boot, requiring manually opening KernelSU and then the app). Now the same two commands are written into /data/adb/service.d/dfroot-ads.sh, and KernelSU executes it as root on every boot — without going through the app, without going through su, and without any authorization prompt;cmd connectivity commands, with the commands, output, and exit codes all printed to the UI log (a successful execution always produces output);The chain that upstream DFRoot ships with, with all code in app/src/main/jni/ (exp.c + two shellcode segments + the kernel module in dirtyfrag-lkm/), compiled into libexp.so and called directly by the App:
splice() to modify the page cache of read-only files;/vendor/lib64/libstagefrighthw.so and then finit_module to load it, setting SELinux to permissive;libc.so / libc++.so, use the modprobe domain to launch the bundled ksud, and late-load KernelSU.Fast (seconds), at the cost of leaving a "already armed this round" trace in /dev/df, and its ksud installation path differs from the manual chain's (see Section 7).
All three binaries are precompiled (byte-for-byte unmodified):
| File | Location | Purpose |
|---|---|---|
libcve43499root.so | jniLibs/arm64-v8a/ | helper, executable ELF, directly execve'd by the App, no Shizuku needed |
cve-2026-43499-app.so | assets/payloads/ | payload, dlopen'd by the helper and then executes the exploit |
ksud-s25u-kdp | assets/payloads/ | KernelSU itself (ksud + embedded kernelsu.ko) |
1. helper --run-payload <payload> <helper> <log> gain root (probabilistic)
2. helper -c "cp ksud …" drop ksud into /data/local/tmp
3. helper --late-load bind mount /system/bin/logcat,
then exec "logcat late-load …" to install KernelSU
Success criteria: both exploit completed and done=1 root=1 appear in the log.
The "Manual" method in the UI runs exactly this (the "Auto" method also falls through to it when the fast channel fails).
Manual button press (in the UI)
└─ Runs in the current process: "Auto" method = fast channel → manual; "Manual" method = manual directly