
HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.
English | Русский
This repository contains a complete, self-contained kit for obtaining persistent root access on the HP Slate 7 2800 running firmware 1.05.18 and kernel Linux 3.0.8+ by exploiting the local vulnerability CVE-2015-1805. The kit was run on the actual tablet, and the result was verified from a fresh ADB session and after a normal reboot.
This is not a universal Android rooting tool. The exploit is specific to this HP kernel configuration. Do not run it on a different model, firmware, or kernel version.
| Parameter | Verified value |
|---|---|
| Manufacturer and model | HP Slate 7 2800 |
| Android | 4.1.1, API 16, build JRO03H |
| Product / device | t7h / pine |
| Processor | Rockchip RK3066, ARMv7 |
| Build fingerprint | hp/t7h/pine:4.1.1/JRO03H/v1.05.18_user:user/release-keys |
| Kernel | 3.0.8+ #13 SMP PREEMPT Tue Jul 28 15:24:30 CST 2015 |
| ABI | 32-bit ARM EABI5 |
| SELinux | not present in the kernel configuration (CONFIG_SECURITY is disabled) |
/system partition | ext4, mounted read-only by default |
You can inspect the device without making any changes:
adb devices -l
adb shell getprop ro.product.model
adb shell getprop ro.build.fingerprint
adb shell getprop ro.build.version.sdk
adb shell cat /proc/version
Alternatively, use the script below. It will refuse to proceed if either the fingerprint or kernel version does not match:
./scripts/check-target.sh
./scripts/check-target.sh ADB_SERIAL
.
├── bin/
│ ├── hp-slate7-cve-2015-1805-root # verified exploit
│ ├── hp-slate7-install-root # installs su into /system
│ └── hp-slate7-su # minimal setuid-root wrapper
├── src/
│ ├── exploit/ # CVE source and device-specific changes
│ ├── installer/install-root.c # installer source
│ └── su/rootsh.S # minimal su source
├── scripts/
│ ├── build.sh # rebuilds all three ELF files
│ ├── check-target.sh # safe compatibility check
│ └── root-device.sh # verifies, uploads, and runs the kit
├── SHA256SUMS # hashes of the verified bin/* files
├── NOTICE # attribution for the original PoC
└── LICENSE # GPL-3.0
| File | Format | Size | Purpose |
|---|---|---|---|
bin/hp-slate7-cve-2015-1805-root | ELF 32-bit ARM EABI5, static, unstripped | 2,722,320 bytes | Exploits the CVE, obtains uid 0, and launches the installer |
bin/hp-slate7-install-root | ELF 32-bit ARM EABI5, static, stripped | 22,596 bytes | Temporarily remounts /system rw, installs su, and restores ro |
bin/hp-slate7-su | ELF 32-bit ARM EABI5, static, stripped | 656 bytes | Calls setresgid(0,0,0) and setresuid(0,0,0), then launches /system/bin/sh |
SHA-256 checksums of the verified binaries:
6bf8ea09efb9f409dfc7aa5efbc3108e5c1a19fc5b07ae913328ef4639a7644f bin/hp-slate7-cve-2015-1805-root
4857c71efc846636afc5b50d7f3c971c6eb68d3760f652086f2a38c5dc50bc4a bin/hp-slate7-install-root
40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e bin/hp-slate7-su
Verification on macOS:
shasum -a 256 -c SHA256SUMS
Verification on Linux:
sha256sum -c SHA256SUMS
Use the files from bin/ on the tablet: these are the exact bytes that were
verified on the device. The build/ directory is intended for local rebuilds
and is not tracked by Git.
CVE-2015-1805 is a flaw in the
pipe_read() and pipe_write() implementations of older Linux kernels. When
an atomic copy fails, the code incorrectly continues traversing the iovec
array, potentially moving a pointer beyond its bounds. As a result, a local
unprivileged process can corrupt memory, crash the kernel, or escalate its
privileges. A detailed explanation of the mechanism was published on
oss-security. The
fixes can be found, among other places, in the upstream Linux commits
637b58c
and f0d1bec.
The tablet's 3.0.8+ kernel proved vulnerable. Before modifying kernel memory,
the same race was tested separately with a harmless probe whose two write
targets were both located in the test process's ordinary memory. It reported
CVE-2015-1805: VULNERABLE, and the tablet remained accessible over ADB.
readv(), memory mapping changes, and
processing a large iovec array in the kernel's vulnerable pipe code.sys_call_table with the address of a small ARM trampoline in the exploit
process.0xffff0008.
On the verified device, the instruction is 0xe59ff410, and its literal
points to vector_swi = 0xc04d0d40.vector_swi and sys_call_table were independently assembled from the
official HP Open Source 1.05.10 kernel archive
(archive SHA-256:
dd69f0468973714fd9ba22cdfea7e96f39f651ee51b9cb537728d9dcadbafda2)
with the rk30_t7h_dvt_defconfig defconfig. Their offset is 0xc4. The
installed firmware has neither OABI nor seccomp, so the table's final
runtime address is 0xc04d0e04.sp, aligns it to the 8,192-byte kernel stack size, and writes -1
only to thread_info.addr_limit at offset 8. It contains no external calls,
prologue, or compiler runtime code.sys_ni_syscall in the HP source; the pointer
restored on the verified kernel is 0xc051900c.addr_limit has been widened, pipe copying reads the current
task_struct, locates cred, and validates the structure using the current
uid/gid values, alignment, reference count, and the real_cred == cred
condition. Only after these checks are the uid/gid values zeroed and the
capability masks filled with ones.uid=0 and launches /data/local/tmp/install-root.
The installer remounts /system rw, copies the payload to
/system/xbin/su, assigns root:root ownership and mode 06755, calls
sync(), and remounts /system read-only.The original current_thread_info() function from the old kernel headers was
incompatible with modern Clang at -O0: an early prototype read an
uninitialized word instead of the sp register and could crash the kernel. In
this repository, it has been replaced with a verified naked ARM trampoline.
The early binary is not included in the repository.
bin/adb from Android SDK Platform Tools;You do not need the Android NDK, Java, Python, fastboot, an unlocked bootloader, a custom recovery, a rooting APK, or network access. The exploit and payload are statically linked.