Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-43499-m3q-azf1 — This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved here. | Kitploit
Tools/GitHubGitHub/bugel/cve-2026-43499-m3q-azf1
Android SecurityPrivilege EscalationReconnaissanceExploitationMobile SecurityPayload DevelopmentBinary Exploitation
GitHubbugel/cve-2026-43499-m3q-azf1

cve-2026-43499-m3q-azf1

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved here.

View Repository
3211 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

GhostLock SELinux park — SM-S948U1 / AZF1 (m3q)

Research snapshot of a working SELinux-only park for Samsung Galaxy S26 Ultra (SM-S948U1, codename m3q) on firmware S948U1UES3AZF1 (GKI 6.12.30-android16-5).

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host uid=0 is not achieved here.

Built from the GhostLock / CVE-2026-43499 line of work: Xiaomi popsicle preload chassis, Samsung Root-My-Galaxy (including the emerald device target and m3q retarget), adapted here for AZF1 park-only. See Attribution.


Warning — read before running

  • Kernel panic risk. The I4 SELinux write leaves residual PI / stack-waiter state. The park path (I4 + R1e settle) is the stable configuration we use in lab; it is still an exploit against a live kernel.
  • Do not run “W2” / second GhostLock punches on this tree after the park (extra emerald / STORE / kptr_restrict / same-stack follow-on writes). Those kernel panic, and on this device have left boots that only come up in safe mode (RescueParty-class recovery), with factory-reset risk if you keep unlocking / recovering badly.
  • Use only on a device you own. Expect reboots, data loss, and Knox-related side effects.
  • Prebuilt bin/preload-4-s1.so is AZF1-specific. Other firmwares need a regenerated target.h.

What this does (W1 park)

  1. KASLR via tracefs (sched_blocked_reason caller → image base).
  2. KernelSnitch reclaim + spray of a forged rt_mutex waiter page (linear-map VA).
  3. I4 emerald: GhostLock residual write stores NULL → selinux_state.enforcing (enforce 1→0).
  4. R1e: short second WAIT_REQUEUE_PI settle so the park survives longer than a raw I4 delayed KP.
  5. Park: process stays alive under LD_PRELOAD (/system/bin/true), reclaim held; logs S1_READY.

Success look:

adb shell getenforce    # Permissive
adb shell pidof true    # non-empty (parked preload)

Helper script also writes same-boot VAs to finish_va.txt (KASLR, spray, static DATA symbols).


What you still need for root

GhostLock on this firmware gives a constrained arbitrary write (NULL and linear-map/spray values into writable .data — not kernel text/rodata as the STORE value) plus Permissive SELinux. Soft-root is still missing:

NeedWhy
Info leak / ARHeap task_struct* or /dev/uhid inode VA (shape-0 GhostLock read and several oracles are dead on AZF1)
Cred / finishOnce task is known: write init_cred (or uid fields) — Samsung KDP/RKP may block naive pointer swaps; working Knox roots typically need host uid=0 then KDP-aware KernelSU (ksud)
Stable post-I4 writeExtra GhostLock punches after I4+R1e are unsafe (enter KP). Do not treat “just STORE again” as the finish

A separate complementary CVE (especially a read primitive still present on June AZF1) is the current high-EV path; polishing more W2 punches on GhostLock alone is not.


Requirements

  • Device: SM-S948U1 on S948U1UES3AZF1 (or rebuild target.h for your build)
  • Host: adb, python3, Android NDK r29+ (to rebuild)
  • USB debugging / shell able to LD_PRELOAD into /system/bin/true

Quick start (prebuilt)

# from a Linux/WSL host with the device attached
export SHARE="$PWD"   # or path where this repo lives
bash park_cal_one.sh
adb shell getenforce   # expect Permissive

park_cal_one.sh defaults SHARE to this repo directory. Override if needed:

SHARE=/path/to/this/repo PRELOAD=/path/to/this/repo/bin/preload-4-s1.so bash park_cal_one.sh

Leave the parked true process alone. Do not chain experimental second punches from other trees.


Rebuild

Windows (PowerShell)

powershell -ExecutionPolicy Bypass -File .\build-park.ps1

Set $ndkBin inside the script if your NDK path differs.

Linux / macOS

make -C source clean preload
# output: source/build/bin/preload.so  (same I4+R1e park flags as preload-4-s1)
cp source/build/bin/preload.so bin/preload-4-s1.so

Default target.h enables Candidate I4 + R1e + S1 park (AZF1_R1_SECOND_WAIT, AZF1_R1_THEN_S1). Do not enable K3/K4/soft second-punch flags for this package.


Layout

bin/preload-4-s1.so     prebuilt park payload (AZF1)
park_cal_one.sh         push + run + VA parse
build-park.ps1          Windows NDK build (park only)
source/                 preload sources + AZF1 target.h
generate_target.py      optional retarget helper (needs your boot.img)

Status summary

StageStatus
SELinux enforce→0 + park (I4+R1e)Works on AZF1 lab device
Further GhostLock “W2” punchesDo not — KP; can force safe-mode-only boot
Host uid=0 / KernelSU installNot in this package — needs leak + Knox-aware finish

Attribution

This snapshot stands on prior public and research work. Credit where it belongs:

ProjectRole in this park
CVE-2026-43499-popsicle (Xiaomi popsicle)GhostLock exploit chassis: LD_PRELOAD harness, KernelSnitch reclaim/spray, fdset-encoded waiter, pselect residual-write core, generate_target.py / Makefile layout
Root-My-Galaxy + Root-My-Galaxy-PayloadsSamsung soft-root framing (W1 park / W2 follow-on), Knox/KDP-aware finish direction, m3q / AZF1 target material, and the tracefs-first KASLR approach used here instead of popsicle’s P0 boot_id slide
emerald (RMG device target)Prior GhostLock port on the emerald device lineage that informed RMG’s Samsung geometry, slide strategy, and W1 SELinux-park ship pattern; this m3q/AZF1 park is in that line, not a from-scratch rewrite

Vulnerability: CVE-2026-43499 (GhostLock — rt_mutex priority-inheritance residual write).

This tree: AZF1 / m3q (SM-S948U1 / S948U1UES3AZF1) port of the popsicle preload sources with RMG/emerald-class Samsung adaptations, cut down to a SELinux-only park harness for researcher-owned hardware. Not a merge back into the Root-My-Galaxy emerald product target.

Download Tool