
CVE-2026-43499 (GhostLock) adaptation for ASUS ROG Phone 5S — UAF trigger + pselect stack reclaim, KASLR leak blocked
Adaptation research of CVE-2026-43499 (GhostLock) on ASUS ROG Phone 5S (ASUS_I005).
Conclusion: Vulnerability triggering and stack reclamation fully verified; the privilege escalation chain was not completed due to insufficient stack overwrite depth.
Specifically:
waiter+0x28..0x40 (pi_tree_entry.rb_left and lock)waiter+0x27See docs/05-limitations.md for detailed analysis.
| Stage | Content | Status |
|---|---|---|
| 0 | UAF trigger (3 threads + CMP_REQUEUE_PI) | ✅ |
| 1 | pselect timeout=0 stack reclamation (shift=10) | ✅ |
| 1.6 | W kernel stack SP leak (perf PERF_SAMPLE_REGS_INTR) | ✅ |
| 2 | Arbitrary address write (requires KASLR slide) | ❌ |
| — | KASLR leak (all 8 sources failed) | ❌ |
| Item | Value |
|---|---|
| Device | ASUS ROG Phone 5S (ASUS_I005) |
| SoC | Snapdragon 888 (SM8350) |
| Android | 13 |
| Kernel | 5.4.210-qgki-perf-gc89cd02a7dfe arm64 |
| SELinux | Enforcing (u:r🐚s0) |
| CapEff | 0 |
CVE-2026-43499 (GhostLock) is a stack UAF in the Linux kernel rtmutex subsystem.
remove_waiter() uses current instead of waiter->task in the proxy lock rollback path,
causing a dangling pointer to remain in task_struct->pi_blocked_on.
_copy_from_user still executesPSELECT_WAITER_WORD_SHIFT = 10See docs/05-limitations.md:
docs/ Analysis documents and timeline
06-research-snapshot.md Complete research snapshot07-iteration-log.md Failed version recordsdisasm/ Key disassembly fragmentsrecon/ Reconnaissance outputinclude/ Symbol table + struct offsetssrc/ PoC source (see src/README.md)scripts/ Analysis scriptslogs/ Run logs (not committed to git)# 1. Extract symbols and offsets (requires vmlinux compiled from ASUS official kernel source)
./scripts/extract_symbols.sh
./scripts/gen_symbols_h.sh
./scripts/extract_offsets.sh
# 2. Compile Stage 0
aarch64-linux-gnu-gcc -static -O2 -pthread \
-o ~/tmp/work/bin/poc_stage0_trigger src/poc_stage0_trigger.c
# 3. Run on device (requires adb shell to the target device)
adb shell /data/local/tmp/poc_stage0_trigger
Toolchain: aarch64-linux-gnu-gcc -static -O2 -pthread
References
· gitchw/ghostlock-cve-2026-43499 Huawei Watch 4 Pro, 5.4.210 (ARM32)
· ccp-p/ghostlock-cve-2026-43499-4.19-k40 Redmi K40, 4.19.157 (aarch64)
· JoinChang/ghostlock-oneplus OnePlus multiple devices, stack layout feasibility
· knowlily/cve-2026-43499-honor Honor failure analysis
Disclaimer
For security research only. Do not use on unauthorized devices.