
PD2229B的43499(ghostlock)可行性研究
| Item | Value |
|---|---|
| Vulnerability Type | Stack Use-After-Free in the rt_mutex / futex PI path |
| Introduced Version | Linux 2.6.39-rc1 (May 2011, commit 8161239a8bcc) |
| Fixed Version | mainline 7.1 (commit 3bfdc63936dd), stable branches: 6.1.175 / 6.6.140 / 6.12.86 / 6.18.27 / 7.0.4 |
| Prerequisite | CONFIG_FUTEX_PI=y (enabled by default in mainstream kernels) |
| CVSS | 7.8 High |
| Exploit Stability | NebuSec original chain 97%, root in ~5 seconds |
| kernelCTF Bounty | $92,337 USD |
Affected kernel ranges:
| Item | Value |
|---|---|
| SoC | Qualcomm SM8475 (Snapdragon 8 Gen 1 Plus) |
| Kernel Version | 5.10.233-gki-g6e61de9f5b58 #1 SMP PREEMPT (Nov 24 2025) |
| Android Version | 15 (OriginOS 5) |
| Build Date | 2025/11/25 |
| Android Security Patch | 2025/11/01 |
CONFIG_FUTEX_PI | y ✅ |
CONFIG_UNMAP_KERNEL_AT_EL0 | y (KPTI enabled) |
kptr_restrict | enforced |
CONFIG_IO_URING | y ✅ (confirmed via vmlinux symbols, and seccomp does not intercept io_uring_setup) |
1. KASLR 绕过 → prefetch timing / PR_SET_MM_MAP auxv
2. UAF 触发 → 三线程 PI 依赖死锁 → FUTEX_CMP_REQUEUE_PI 返回 -EDEADLK
3. 栈回收 → PR_SET_MM_MAP 将 auxv 拷贝到 waiter 栈帧
4. rb_erase 受限写 → 覆写 inet6_protos[IPPROTO_UDP]
5. CEA + ROP → 控制流劫持
6. core_pattern 翻转 → root shell (97% 成功率)
| Stage | Status | Description |
|---|---|---|
| 1. KASLR Bypass | ✅ Implemented | perf_event_open + callchain sampling side channel (same method as the OPPO Find X6 Pro 5.15.149 adaptation) |
| 2. UAF Trigger | ✅ Implemented | Three-thread PI deadlock succeeds, FUTEX_CMP_REQUEUE_PI returns -EDEADLK |
| 3. Stack Reclaim Primitive | ❌ Architectural failure | Stack frames of all known syscalls do not overlap the waiter (see Section III) |
| 4. rb_erase Constrained Write | ❌ Blocked | Prerequisite not met |
| 5. inet6_protos Overwrite | ❌ Not started | Depends on stage 4 |
| 6. ROP / Control Flow Hijack | ❌ Not started | Depends on stage 5 |
| 7. Root Shell | ❌ Not started | Depends on stage 6 |
futex 路径总深度:
__arm64_sys_futex 0x90
+ do_futex 0xc0
+ futex_wait_requeue_pi 0x1b0
= 0x300
waiter 位置 = SYS_SP - 0x300 + 0x20 = SYS_SP - 0x2e0
pselect 路径:
core_sys_select 栈帧 0x1c0, stack_fds 在 sp+0x50
覆盖区间: SYS_SP - 0x1c0 + 0x50 = SYS_SP - 0x170 起
与 waiter (SYS_SP - 0x2e0) 差距 0x170 (368 字节) → 不重叠
| # | Method | Syscall | PD2229 Result | Core Failure Reason |
|---|---|---|---|---|
| 1 | stamp_prctl | PR_SET_MM_MAP | ❌ EPERM | Android hard block |
| 2 | stamp_pselect | pselect6 (NFDS=320) | ❌ No overlap | waiter is 120B below fd_set |
| 3 | stamp_pselect | pselect6 (NFDS>336) | ❌ Heap allocation | kvmalloc path |
| 4 | stamp_socket | MCAST_JOIN_SOURCE_GROUP | ❌ Insufficient overwrite | Only writes the lock field |
| 5 | stamp_sendmsg | sendmsg | ❌ 80B from waiter | Stack frame 0x90 too shallow |
| 6 | stamp_sendmmsg | sendmmsg | ❌ 112B from waiter | Insufficient stack frame |
| 7 | stamp_recvmmsg | recvmmsg | ❌ Zeroes task/lock | 0x1d0 stack frame corrupts key pointers |
| 8 | stamp_process_vm | process_vm_writev | ❌ No overlap | Child thread stack allocated separately |
| 9 | stamp_keyctl | KEYCTL_INSTANTIATE_IOV | ❌ EOPNOTSUPP | Syscall unsupported + stack frame 0x40 |
| 10 | stamp_tcp | TCP_ZEROCOPY_RECEIVE | ❌ Insufficient stack frame | Estimated depth not enough |
| 11 | stamp_futex | FUTEX_CMP_REQUEUE_PI recursion | ❌ Logically infeasible | Corrupts the UAF window |
| 12 | binder ioctl | BINDER_WRITE_READ | ❌ EACCES | shell lacks /dev/binder permission |
| 13 | poll | poll | ❌ Heap allocation | pollfd is on the heap |
| 14 | epoll_wait | epoll_wait | ❌ Frame too shallow | Stack frame 0xE0 |
| 15 | sched_setattr | sched_setattr | ❌ Insufficient depth | Stack frame 0xb0 |
| 16 | timerfd_settime | timerfd_settime | ❌ No stack copy | No large stack buffer |
| 17 | io_uring_register | IORING_REGISTER_* | ❌ Double failure | ①Stack frame is only 0xF0, and the copy_from_user target is fixed at sp+0x8 (424 bytes away from the waiter's sp+0x1D0); ②although io_uring_setup is not intercepted by seccomp (returns EFAULT instead of ENOSYS), the stack layout does not match |
17/17 all failed.
The stack layout produced by PD2229's SM8475 5.10 GKI compiler (PGO + LTO + BOLT) causes core_sys_select's stack_fds and futex_wait_requeue_pi's rt_mutex_waiter to be architecturally non-overlapping. This is an objective fact determined by the compiler, not an exploit technique issue.
The JoinChang repository explicitly states: "The pselect stack overlay only works when the freed rt_mutex_waiter lands within the user-controllable region of the stack_fds buffer" — PD2229 does not satisfy this condition.
PR_SET_MM_MAP copies auxv to the kernel stackPR_SET_MM_MAP is blocked by EPERM on AndroidPSELECT_SHIFT = -2