
SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko. Device-verified 2026-08-12.
CVE-2026-43499 temporary root → LD_PRELOAD channel bypasses DEFEX → no-LTO clang-12 build of kernelsu.ko → full su + KernelSU Manager functionality
Status: ✅ Verified on real device 2026-08-12 (firmware
F9360ZCSAIZF1, kernel5.10.236-android12-9-2755199-abF9360ZCSAIZF1)This project documents a complete, reproducible procedure for achieving KernelSU root on a bootloader-locked Samsung device: no BL unlock, no boot.img flashing, no Odin required.
TL;DR (English): This repo documents a fully device-verified jailbreak path for a locked-bootloader Samsung Galaxy Z Fold4 (SM-F9360, SM8450, kernel 5.10.236, firmware F9360ZCSAIZF1): a CVE-2026-43499 (rtmutex UAF, fixed in July-2026 firmware) exploit chain grants temporary kernel-domain root; a custom LD_PRELOAD constructor .so bypasses Samsung's DEFEX execve interceptor to init_module() a KernelSU LKM built with the exact device toolchain (AOSP clang 12.0.5 r416183b) and with LTO disabled — the two factors that make the module loadable and its init executable on this CFI/LTO hardened kernel. Result: su works (uid=0, context=u:r:ksu:s0) and KernelSU Manager v3.2.5 recognizes the kernel. Root is in-memory only: every reboot requires re-running the exploit (~3 min, scripted). All pitfalls and dead ends (fake exports, CRC patching, ksud late-load, LTO function-sections layout) are documented below.
| Item | Status |
|---|---|
Temporary root (kernel domain kernel:s0) | ✅ Achieved reliably (9 consecutive successes) |
KernelSU module load (init_module) | ✅ kernelsu ... Live (O) |
| Full KSU init execution | ✅ All 15 instrumentation marks green |
su command | ✅ uid=0(root) gid=0(root) context=u:r:ksu:s0 |
| KernelSU Manager v3.2.5 | ✅ Recognizes kernel version (supercall detection passes), works under SELinux enforcing mode |
| Bootloader unlock | ❌ Not required |
| Flashing/modifying partitions | ❌ Not required |
Fundamental limitation: BL lock → root is purely in-memory. After every reboot, the exploit must be re-run and the module reloaded (full procedure ~3 minutes, scripted). The ksud userspace daemon cannot be deployed (DEFEX blocks execve, see §10-4), but su / supercall / Manager are all handled directly by the kernel sucompat, with no dependency on ksud.
Warning: rmmod kernelsu will immediately panic and reboot the device (RKP-protected syscall-table restore path) — never unload it.
fastboot oem unlock does not exist; any persistent root (magisk/kernel patch) requires flashing boot.img, and a locked BL rejects all self-signed images.CONFIG_CFI_CLANG=y + Full LTO. The only source of mod->init is the CFI jump-table slot __cfi_jt_init_module; indirect calls must go through a .cfi_jt table entry, otherwise the CFI check panics immediately.__ksymtab export table, so a normal insmod cannot resolve them (Unknown symbol).IGNORE_MODVERSIONS/IGNORE_VERMAGIC flags all lead to the try_to_force_load() dead end.sarabpal-dev/IonStack-S22U (b0q / S22U, exp32 route).LD_PRELOAD constructor .so is the only exempt channel for executing arbitrary code in the root domain.ksud late-load) was designed precisely for BL-locked devices: no boot flashing, just runtime init_module.┌─ Layer 1: CVE-2026-43499 temporary root
│ ionstack-q4q exploit (KASLR leak → mm reclaim → exp32 32-bit stack stamp
│ → CFI r/w → pipe physrw → UMH root daemon)
│ → /data/local/tmp/cve-2026-43499-root -c '<cmd>' = kernel:s0 domain root command channel
│
├─ Layer 2: LD_PRELOAD .so loading channel (DEFEX bypass)
│ DEFEX intercepts execve of any new ELF in the kernel domain (Killed); LD_PRELOAD constructor
│ execution is exempt → ksu-load.so inside the /system/bin/true process:
│ reads ko → manually relocates 201 UND symbols via /proc/kallsyms (SHN_ABS + st_value=absolute address)
│ → vermagic patch (needed for older versions) → init_module() → success
│
└─ Layer 3: KernelSU kernel module (no-LTO clang-12 build)
Full init execution, all 15 marks green → sucompat (allow_shell=1) + supercall available
| Item | Value |
|---|---|
| Model | SM-F9360 (Galaxy Z Fold4, q4q) |
| SoC | SM8450 (Snapdragon 8+ Gen 1) |
| Firmware | F9360ZCSAIZF1 (built ≤ 2026-06, contains the CVE) |
| Kernel | 5.10.236-android12-9-2755199-abF9360ZCSAIZF1 |
| Device compiler | AOSP clang 12.0.5 (r416183b, c935d99d7cf) (confirmed via /proc/version) |
| Exact vermagic | 5.10.236-android12-9-2755199-abF9360ZCSAIZF1 SMP preempt mod_unload modversions aarch64 |
Different firmware = different kallsyms / layout / vermagic, requiring re-adaptation of target.h and a rebuild. See §11.