Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
tcp-zerocopy-sm — ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel | Kitploit
Tools/GitHubGitHub/meowkis/tcp-zerocopy-sm
Android SecurityPrivilege EscalationExploitationMobile SecurityBinary ExploitationArchived
GitHubmeowkis/tcp-zerocopy-sm

tcp-zerocopy-sm

ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel

View Repository
2141 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Investigation is closed. Working fork: https://github.com/soumarcelino/Root-My-Galaxy-SM-S918B

Read this -> https://github.com/BuSung-dev/Root-My-Galaxy-Payloads/issues/160#issuecomment-5227077583

Version License License

Attempts to cause rights elevation w GhostLock via TCP Zerocopy.

Designed expecially for 5.15.* samsung kernel

[!WARNING] Do not rely on current payload tests. After reviewing the exploit code more carefully, I realized I had misidentified the CVEs associated with the TCP zerocopy path. The standalone payload tests I ran were incorrect. Isolated payload tests without the full exploit chain prove nothing. I will update this issue once the complete port is tested.

[!IMPORTANT] The only reliable way to determine if this vector still works on the SM-S918B is to port the full Pixel 9 exploit (including the GhostLock dangling waiter setup, CFI stage, and configfs R/W primitives) and observe whether it reaches main tcp route done=1. I will continue working on this port, but there is no ETA.

🚧 Work in progress (v0.1):
Investigating the flow to build porting strategy .

Project

CyberMeowfia/exploit/src/ is reference only! Samsung device config was added for testing here and doesn't mean anything. The actual port will be in src/

Current target

PropertyValue
DeviceSamsung Galaxy S23 Ultra, dm3q / SM-S918B
BuildS918BXXSAFZF5
Android version16
Kernel5.15.189-android13-8-33413713-abS918BXXSAFZF5
Fingerprintsamsung/dm3qxxx/dm3q:16/BP4A.251205.006/S918BXXSAFZF5:user/release-keys
ArchitectureARM64
Kernel text base0xffffffc008000000
Physical base0x80000000
Physical kernel load address0x80080000

Test payloads are stored in payloads/. The active constants are stored in target.h.

You can verify if your S23 family phone is vulnerable by compiling and running test_tcp_zc.c

Compiling

export NDK=~/Android/Sdk/ndk/android-ndk-r29 #path_to_ndk

$NDK/toolchains/llvm/prebuilt/linux-x86_64/bin/aarch64-linux-android29-clang -static -O2 test_tcp_zc.c -o test_tcp_z

Running the penetration test

adb push test_tcp_zc /data/local/tmp/
adb shell chmod +x /data/local/tmp/test_tcp_zc
adb shell /data/local/tmp/test_tcp_zc

What should be happened

If kernel panics then is vulnerable to this exploit!

Kimi's analyzed fops.c

Click to view
Download Tool