
Local privilege escalation exploit for Redmi K50G/POCO F4 GT using CVE-2026-43499 (futex UAF) to gain temporary root and load KernelSU without unlocking bootloader.
One-click temporary Root without unlocking BL. Uses the GhostLock (CVE-2026-43499, futex PI Use-After-Free) local privilege escalation chain to obtain a root anchor, then mounts the kernelsu module into the running kernel via KernelSU 3.3.0 late-load, working with the KSU module to keep SELinux Permissive and fix networking.
Target device: Redmi K50G / POCO F4 GT — codename
ingres, SoC SM8450 (Snapdragon 8 Gen 1) System: Android 14, UKQ1.240624.001, kernel 5.10.209-android12 (KMIandroid12-5.10) Status: ✅ Temporary Root verified working on real device
| File | Purpose |
|---|---|
exploit | GhostLock privilege escalation binary (ARM64 PIE, not stripped). Internally contains KernelSnitch mm collision locating, futex PI UAF stack overwrite, kernel anchor root, su daemon, embedded libksud.so and KSU late-load logic |
Root-K50G.bat | Windows one-click script (locates files relative to its own directory, double-click to use): detect device → push files → run privilege escalation → directly enter root shell |
ksu_loader.sh | Executed by the rooted kernel anchor: libksud.so late-load --kmi 5.10.209-android12 loads KernelSU, and sequentially triggers the post-fs-data / services / boot-completed stages |
ksu-module/chuxin_permissive_netfix/ | KernelSU module (module.prop + service.sh): monitors enforce=0 every 2 seconds, and resets anti-tamper properties, restarts netd, enables wifi/data to fix network disconnection |
adb/ | Built-in adb tools (portable, no installation required) |
adb驱动无需重启.exe | Xiaomi driver one-click installation tool |
The entire chain consists of four steps:
FUTEX_WAIT_REQUEUE_PI + FUTEX_CMP_REQUEUE_PI) creates a dangling rt_mutex_waiter on the kernel stack;rt_mutex_adjust_prio_chain traversal, yielding controlled kernel read/write primitives.cred via the write primitive (uid/gid=0, full caps, kernel SID), obtaining a root anchor process (anchor: ROOT uid=0 in the run log);SHELL_ROOT=1) and su daemon (SU_DAEMON=1, /data/local/tmp/su).kernelsu.ko is loaded into the running kernel via libksud.so late-load --kmi 5.10.209-android12 (no flashing/patching boot image required, precisely matching the device's current KMI);ksu_loader.sh sequentially executes post-fs-data, services, boot-completed, allowing the KernelSU management framework (ksud) to start up normally.chuxin_permissive_netfix is installed into /data/adb/modules/: its service runs in the ksu domain (with security:setenforce permission), writing enforce back to 0 every 2 seconds, counteracting ksud's behavior of flipping SELinux back to Enforcing after boot-completed (preventing AVC from rejecting su socket + network disconnection);ro.boot.flash.locked / verifiedbootstate / warranty bit properties and restarts netd, fixing networking after Root.Root-K50G.bat;id to verify uid=0(root);/data/local/tmp/su -c id.adb push exploit /data/local/tmp/exploit
adb push ksu_loader.sh /data/local/tmp/ksu_loader.sh
adb shell chmod 755 /data/local/tmp/exploit /data/local/tmp/ksu_loader.sh
adb shell "env NO_COLOR=1 SE_LINUX=1 KSU_LOADER=1 SHELL_ROOT=1 SU_DAEMON=1 SUSPECT_CPU=99999 KS_MAX_TRIES=8 /data/local/tmp/exploit"
Verify after running:
adb shell /data/local/tmp/su -c id
# uid=0(root) gid=0(root) ...
| Variable | Default | Meaning |
|---|---|---|
NO_COLOR | 0 | Disable colored logging |
SE_LINUX | 0 | Enable SELinux Permissive flip (kernel anchor directly writes enforce) |
KSU_LOADER | 0 | Execute ksu_loader.sh within the root anchor (KernelSU late-load) |
SHELL_ROOT | 0 | Fork root shell within the anchor |
SU_DAEMON | 0 | Start /data/local/tmp/su daemon within the anchor |
SUSPECT_CPU | - | Specify suspect CPU (anchor binding), 99999 means automatic |
KS_MAX_TRIES | - | KernelSnitch mm collision/anchor attempt limit |
chuxin_permissive_netfix module's service.sh automatically resets properties and restarts netd (also effective after flashing modules like LSPosed);The contents of this repository are for security research and personal device testing only. Privilege escalation/modifying system state carries certain risks; improper operation may brick the device or cause data loss. Please use it only after fully understanding the principles and accepting the consequences yourself, and do not use it for illegal purposes.
Reference: CVE-2026-43499 (GhostLock) — Linux kernel futex priority inheritance UAF, affecting kernels 2.6.39 ~ 7.1, allowing local privilege escalation.