Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
GhostLock-for-OnePlus — (CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加设备。 | Kitploit
Tools/GitHubGitHub/p2p3p/ghostlock-for-oneplus
Android SecurityPrivilege EscalationExploitationPost-ExploitationLearning & EducationPayload DevelopmentBinary Exploitation
GitHubp2p3p/ghostlock-for-oneplus

GhostLock-for-OnePlus

(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加设备。

View Repository
3613482 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

GhostLock — OnePlus

中文

Kernel exploit targeting locked-bootloader OnePlus devices. Uses CVE-2026-43499 to obtain root access without unlocking the bootloader or modifying boot.img.

Authorized security research and educational purposes only.


Table of Contents

  • Vulnerability Overview
  • Supported Devices
  • Prerequisites
  • Building
  • Usage
  • Run Modes
  • Technical Details
  • File Structure
  • Adding New Devices
  • FAQ

Vulnerability Overview

ItemDetail
CVECVE-2026-43499
TypeFutex PI (Priority Inheritance) Use-After-Free
ScopeLinux kernel 2.6.39 ~ 7.1
Fixed inMainline 7.1 (commit 3bfdc63936dd)
Android StatusGKI 6.12.x still vulnerable

Root Cause

The pselect6 syscall copies fd_set to the kernel stack. When combined with the futex PI waiter mechanism, a freed stack frame can be reallocated as a rt_mutex_waiter struct. During PI chain traversal, rb-tree rebalancing writes controlled data to arbitrary kernel addresses.

Chain

futex PI UAF (CVE-2026-43499)
  ├─ Forge rt_mutex_waiter object
  ├─ Control kernel stack via pselect/select fd_set layout
  ├─ Trigger rt_mutex PI operation for arbitrary write
  ├─ Write 1: selinux_state.enforcing = 0
  └─ Write 2: cred → init_cred (uid=0, full capabilities)

Supported Devices

DeviceCodenameSoCKernelFirmwareStatus
OnePlus Ace 6TPLR110SM8845 (Snapdragon 8s Elite)6.12.38-android16-5-...-ab14275539-4kColorOS 16.0.2.403✅ Verified
OnePlus Ace 6TPLR110SM8845 (Snapdragon 8s Elite)6.12.38-android16-5-...-ab14552068-4kColorOS 16.0.8.301✅ Verified
OnePlus 15PLK110SM8845 (Snapdragon 8s Elite)6.12.23-android16-5-...-ab14541642-4k—✅ Verified

Other OnePlus devices on the same SoC family, Android 16, or kernel 6.12.x can be adapted via boot.img offset extraction.


Prerequisites

ksud (Required for KernelSU)

GhostLock handles privilege escalation. KernelSU installation requires ksud (bundled with KMI-specific kernelsu.ko):

SourceNotes
ReSukiSU APK (recommended)Install ReSukiSU; the APK bundles libksud.so
CI ReleaseDownload from ReSukiSU CI (ksud-aarch64-linux-android.zip)

Without ksud, the exploit still gets uid=0 root shell, but KernelSU won't be installed and su won't persist.


Building

Prerequisites

  • Android NDK (r25+)
  • Set ANDROID_NDK_HOME or ANDROID_NDK_ROOT

Build

# Default (API 35)
make

# Specify API level
make API=34

# Specify NDK path
NDK=/path/to/android-ndk make

Artifact

ghostlock — statically linked ARM64 ELF executable.


Usage

One-time Setup

# 1. Enable ADB TCP mode
adb tcpip 5555

# 2. Push ADB key (required for bootstrap mode)
adb push ~/.android/adbkey /data/local/tmp/a/adbkey

# 3. Push the exploit
adb push ghostlock /data/local/tmp/a/e
adb shell chmod 755 /data/local/tmp/a/e

After first success, resetprop automatically sets persist.adb.tcp.port=5555, allowing fully automatic runs on subsequent reboots.


Run Modes

Full Exploit (ADB shell context)

/data/local/tmp/a/e
  • perf available, precise child task_struct leaking
  • Two-stage: W1 disable SELinux → W2 privilege escalation → KernelSU load

Bootstrap Mode (App context, seccomp restricted)

/data/local/tmp/a/e --bootstrap
  1. Write 1 → disable SELinux
  2. Use freed permissions to setprop enable ADB TCP 5555
  3. Built-in Mini ADB client connects to 127.0.0.1:5555
  4. RSA authentication with pre-pushed key
  5. Full exploit execution via ADB shell (no seccomp)

Write 1 Only

/data/local/tmp/a/e --write1
  • Up to 20 attempts
  • Useful for debugging or temporary SELinux disable

Technical Details

1. Runtime Kernel Matching

Offsets stored in src/devices/offsets.h lookup table, keyed by uname -r. Program auto-matches at startup; unknown kernels are rejected.

static const struct kernel_offsets known_offsets[] = {
  OFFSETS_ENTRY("6.12.38-android16-5-...-ab14275539-4k", ...),
  OFFSETS_ENTRY("6.12.38-android16-5-...-ab14552068-4k", ...),
  OFFSETS_ENTRY("6.12.23-android16-5-...-ab14541642-4k", ...),
  { .uname_r = NULL }  /* sentinel */
};

Offset Sources

TypeCountExtraction
kallsyms global symbols28tools/extract_target.py
BTF struct fields57tools/extract_btf.py
Derived values9Auto-calculated
Fixed constants12Hardcoded

BTF-verified Structs

StructFieldsPurpose
task_struct17Process descriptor, cred, seccomp
rt_mutex_waiter6UAF forge target
cred4Credentials, capabilities
seccomp3Seccomp filter state
pipe_inode_info11Pipe buffer operations
file_operations13Fake fops table
mm_struct1Memory descriptor owner

2. KASLR Bypass

SLIDE Mode — boot_id Leak

When kernel pointers are restricted (kptr_restrict), leak the base address via boot_id overwritten with a kernel address:

Read /proc/sys/kernel/random/boot_id
  └─ UUID contains nfulnl_logger address
      └─ KASLR slide = leaked_addr - image_offset
          └─ kaslr_base

FOPS/CFI Mode — fops Table Leak

When ashmem device is accessible, use configfs read/write primitives to read function pointers from the ashmem fops table and compute KASLR offset.

3. Kernel Heap Spray

Forge kernel objects on order-3 (32KB) pages:

  • Fake file_operations — hijack ashmem miscdevice fops pointer
  • Fake rt_mutex_waiter — simulate PI chain waiter node
  • Fake task_struct — task reference during PI traversal
  • Fake rt_mutex (lock) — correct waiter/owner information

Implemented via SKB (socket buffer) + KernelSnitch:

  • KernelSnitch — futex hash collision to leak mm_struct addresses
  • SKB spray — sendmsg to fill kernel heap

4. Physical Memory R/W (Pipe)

After obtaining KASLR base, use pipe buffers for physical-level memory access:

1. Locate pipe buffer in physmap
2. Forge pipe_buffer ops table pointing to known pipe_buf_ops
3. Hijack pipe_buffer.page to target physical address
4. Arbitrary physical read/write via normal pipe operations

Supported: pipe_read64, pipe_write64, pipe_phys_read_data, pipe_phys_write_data

5. Two-Stage Write

Write 1 — Disable SELinux

Target: selinux_state.enforcing (offset 0x00)
Method: child-node PI write → forge waiter __rb_parent_color
        pointing to selinux_enforcing - 8
        rb-tree rebalance writes 0x00

Write 2 — Escalate to Root

Target: child process cred pointer
Method: 1. fork child → perf_find_task() locate task_struct
        2. calculate cred field offset
        3. child-node PI write → cred = init_cred (uid=0, full caps)
        4. clear seccomp (TIF_SECCOMP + seccomp struct zeroed)

Capability readback verification is performed after cred overwrite.

6. Built-in Mini ADB Client

src/core/miniadb.c — lightweight ADB protocol client for bootstrap mode:

1. TCP connect 127.0.0.1:5555
2. A_CNXN → connection request
3. A_AUTH → RSA token challenge
4. dlopen("libcrypto.so") → PEM_read_bio_RSAPrivateKey → RSA_sign
5. A_AUTH (AUTH_SIGNATURE) → signed response
6. A_CNXN → connection established
7. A_OPEN "shell:/data/local/tmp/a/e" → full exploit
Download Tool