Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-64560-a16 — CVE-2026-64560 toolkit: Go single-binary toolchain + realme RMX5010 (A16, SM8750) target port | Kitploit
Tools/GitHubGitHub/become-illusory/cve-2026-64560-a16
Android SecurityPrivilege EscalationExploit FrameworksVulnerability AnalysisExploitationReverse EngineeringMobile SecurityUtilities & FrameworksShellcode Generation

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Payload Development
Binary Exploitation
GitHubbecome-illusory/cve-2026-64560-a16

cve-2026-64560-a16

CVE-2026-64560 toolkit: Go single-binary toolchain + realme RMX5010 (A16, SM8750) target port

View Repository
12 days agoNot yet reviewed

CVE-2026-64560 — 工具链 + 多目标移植

CVE-2026-64560 是 Linux 内核 posix-cpu-timers 的 use-after-free (本地无特权竞态,CVSS 3.1 = 7.8;6.6.118 未修复,6.6.147 才修)。 这个仓库有两件事:把上游只能靠一堆 Python 脚本驱动的工具链做成单个静态 Go 二进制, 以及补上上游没有的 realme RMX5010(A16 / SM8750) 目标。

[!WARNING] 这是实验性内核 exploit 代码。它可能重启设备、破坏内核状态或造成数据丢失。 只在你拥有或获明确授权的设备上使用。先备份。

目标

profile设备内核状态
rmx5010-a16realme RMX5010 / RE6018L1,A16 BP2A.250605.0156.6.118-android15-8-g93e223c276e7-abogki500782043-4k本仓库新增;静态载荷在真机通过 --preflight 门禁,完整提权尚未实机验证
dadaXiaomi 156.6.118-android15-8-gb9cc6ec16bc8-…-4k上游原样保留(见 上游说明)
op13OnePlus 13与上游一致上游原样保留

直接拿现成产物

不用装 Go、不用装 Python:

  • Release:打 v* 标签时自动发布,含各平台工具 + 各目标载荷 + SHA256SUMS.txt
  • Actions artifacts:每次 push 到 main 都会出
    • cve64560-<os>-<arch>:linux/amd64、linux/arm64、android/arm64、darwin/arm64、windows/amd64
    • payloads:各 profile 的 aarch64 静态载荷(rmx5010-a16-…、op13-…, 各写各的目录,不再互相覆盖)

android/arm64 那个可以直接 adb push 到 /data/local/tmp 在手机上跑。

自己编

root@kitploit:~
go build -o cve64560 ./gotool                 # 工具(纯 Go,无依赖)
./cve64560 build --profile profiles/rmx5010/rmx5010-40850e5ff6a5.json   # 载荷(需要 cc)

命令行一览、--dry-run 空跑、profile 怎么推导,见 docs/GOTOOL.md。

工具链为什么是 Go

原来的流程要 python3 + tools/*.py + 一堆 shell:测试机上没有 python, 手机上更不可能有。现在一个静态二进制覆盖 kallsyms → derive → render → patch → build → campaign 全流程, 交叉编译到哪都能跑。

Python 实现没有删:它留在 tools/ 里当参考实现和 CI 对拍基线, CI 会对每个 profile 各跑一遍 Go 和 Python 然后 diff -r,逐字节不一致就红。

CI 干了什么(.github/workflows/build.yml)

目录

root@kitploit:~
gotool/           Go 工具链(一个命令一个文件)
profiles/         目标 profile(每目标一份 JSON,渲染的唯一真源)
src/              上游模板 + 已渲染的设备源码
tools/            上游 Python 参考实现 + musl/bionic 兼容层 + CI 脚本
scripts/          上游的战役/测量脚本(Go 版见 gotool/cmd_campaign.go)
targets/          每个目标的内核符号/偏移记录
symbols/          两个出货 profile 的内核符号表(其余目标的属于派生数据)
docs/GOTOOL.md    Go 工具链文档

安全边界

仓库不含固件镜像、设备密钥或设备唯一标识。需要厂商内核镜像才能复现的步骤 (抽符号、推 profile)自带原始镜像,不进仓库。

唯一的例外是那两个出货 profile 的内核符号表(symbols/symbols_*.json,各约 9 MB):build 找不到表会直接失败(不出一个常量没被校验过的载荷),而 CI 手上 没有内核 Image,重建不出表来。它们只含符号名和地址,不含镜像本身。

载荷是临时 root:重启即失效,不落盘、不改分区。

Download Tool
job作用
gotool5 个平台交叉编译 + gofmt/go vet/go test
parityGo 与 Python 输出逐字节比对;tools/golden.sha256 硬校验黄金产物
payload在 arm64 Alpine 容器(qemu)里编译载荷,工具链与当初真机验证过的 aarch64 musl gcc 同类
releasetag 自动发 Release