Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
hp-slate7-root-kit — HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805. | Kitploit
Tools/GitHubGitHub/valentineus/hp-slate7-root-kit
Android SecurityPrivilege EscalationPersistence MechanismsVulnerability AnalysisExploitationPost-ExploitationMobile SecurityPayload DevelopmentBinary Exploitation
GitHubvalentineus/hp-slate7-root-kit

hp-slate7-root-kit

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

1181 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

Root for the HP Slate 7 2800 on Android 4.1.1

English | Русский

This repository contains a complete, self-contained kit for obtaining persistent root access on the HP Slate 7 2800 running firmware 1.05.18 and kernel Linux 3.0.8+ by exploiting the local vulnerability CVE-2015-1805. The kit was run on the actual tablet, and the result was verified from a fresh ADB session and after a normal reboot.

This is not a universal Android rooting tool. The exploit is specific to this HP kernel configuration. Do not run it on a different model, firmware, or kernel version.

Verified configuration

ParameterVerified value
Manufacturer and modelHP Slate 7 2800
Android4.1.1, API 16, build JRO03H
Product / devicet7h / pine
ProcessorRockchip RK3066, ARMv7
Build fingerprinthp/t7h/pine:4.1.1/JRO03H/v1.05.18_user:user/release-keys
Kernel3.0.8+ #13 SMP PREEMPT Tue Jul 28 15:24:30 CST 2015
ABI32-bit ARM EABI5
SELinuxnot present in the kernel configuration (CONFIG_SECURITY is disabled)
/system partitionext4, mounted read-only by default

You can inspect the device without making any changes:

adb devices -l
adb shell getprop ro.product.model
adb shell getprop ro.build.fingerprint
adb shell getprop ro.build.version.sdk
adb shell cat /proc/version

Alternatively, use the script below. It will refuse to proceed if either the fingerprint or kernel version does not match:

./scripts/check-target.sh
./scripts/check-target.sh ADB_SERIAL

Repository contents

.
├── bin/
│   ├── hp-slate7-cve-2015-1805-root  # verified exploit
│   ├── hp-slate7-install-root        # installs su into /system
│   └── hp-slate7-su                  # minimal setuid-root wrapper
├── src/
│   ├── exploit/                      # CVE source and device-specific changes
│   ├── installer/install-root.c      # installer source
│   └── su/rootsh.S                   # minimal su source
├── scripts/
│   ├── build.sh                      # rebuilds all three ELF files
│   ├── check-target.sh               # safe compatibility check
│   └── root-device.sh                # verifies, uploads, and runs the kit
├── SHA256SUMS                        # hashes of the verified bin/* files
├── NOTICE                            # attribution for the original PoC
└── LICENSE                           # GPL-3.0

File formats and purposes

FileFormatSizePurpose
bin/hp-slate7-cve-2015-1805-rootELF 32-bit ARM EABI5, static, unstripped2,722,320 bytesExploits the CVE, obtains uid 0, and launches the installer
bin/hp-slate7-install-rootELF 32-bit ARM EABI5, static, stripped22,596 bytesTemporarily remounts /system rw, installs su, and restores ro
bin/hp-slate7-suELF 32-bit ARM EABI5, static, stripped656 bytesCalls setresgid(0,0,0) and setresuid(0,0,0), then launches /system/bin/sh

SHA-256 checksums of the verified binaries:

6bf8ea09efb9f409dfc7aa5efbc3108e5c1a19fc5b07ae913328ef4639a7644f  bin/hp-slate7-cve-2015-1805-root
4857c71efc846636afc5b50d7f3c971c6eb68d3760f652086f2a38c5dc50bc4a  bin/hp-slate7-install-root
40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e  bin/hp-slate7-su

Verification on macOS:

shasum -a 256 -c SHA256SUMS

Verification on Linux:

sha256sum -c SHA256SUMS

Use the files from bin/ on the tablet: these are the exact bytes that were verified on the device. The build/ directory is intended for local rebuilds and is not tracked by Git.

Vulnerability used

CVE-2015-1805 is a flaw in the pipe_read() and pipe_write() implementations of older Linux kernels. When an atomic copy fails, the code incorrectly continues traversing the iovec array, potentially moving a pointer beyond its bounds. As a result, a local unprivileged process can corrupt memory, crash the kernel, or escalate its privileges. A detailed explanation of the mechanism was published on oss-security. The fixes can be found, among other places, in the upstream Linux commits 637b58c and f0d1bec.

The tablet's 3.0.8+ kernel proved vulnerable. Before modifying kernel memory, the same race was tested separately with a harmless probe whose two write targets were both located in the test process's ordinary memory. It reported CVE-2015-1805: VULNERABLE, and the tablet remained accessible over ADB.

Privilege-escalation chain

  1. The exploit creates a race between readv(), memory mapping changes, and processing a large iovec array in the kernel's vulnerable pipe code.
  2. The resulting write primitive temporarily replaces the unused entry 222 in sys_call_table with the address of a small ARM trampoline in the exploit process.
  3. The table address is calculated through the high vector at 0xffff0008. On the verified device, the instruction is 0xe59ff410, and its literal points to vector_swi = 0xc04d0d40.
  4. vector_swi and sys_call_table were independently assembled from the official HP Open Source 1.05.10 kernel archive (archive SHA-256: dd69f0468973714fd9ba22cdfea7e96f39f651ee51b9cb537728d9dcadbafda2) with the rk30_t7h_dvt_defconfig defconfig. Their offset is 0xc4. The installed firmware has neither OABI nor seccomp, so the table's final runtime address is 0xc04d0e04.
  5. The trampoline consists of exactly six ARM instructions. It obtains the current sp, aligns it to the 8,192-byte kernel stack size, and writes -1 only to thread_info.addr_limit at offset 8. It contains no external calls, prologue, or compiler runtime code.
  6. Immediately after the temporary syscall returns, entry 222 is restored from entry 223. Both entries are sys_ni_syscall in the HP source; the pointer restored on the verified kernel is 0xc051900c.
  7. Once addr_limit has been widened, pipe copying reads the current task_struct, locates cred, and validates the structure using the current uid/gid values, alignment, reference count, and the real_cred == cred condition. Only after these checks are the uid/gid values zeroed and the capability masks filled with ones.
  8. The process obtains uid=0 and launches /data/local/tmp/install-root. The installer remounts /system rw, copies the payload to /system/xbin/su, assigns root:root ownership and mode 06755, calls sync(), and remounts /system read-only.

The original current_thread_info() function from the old kernel headers was incompatible with modern Clang at -O0: an early prototype read an uninitialized word instead of the sp register and could crash the kernel. In this repository, it has been replaced with a verified naked ARM trampoline. The early binary is not included in the repository.

Required software

To use the ready-made files from bin/

  • a computer running macOS or Linux; Windows is also possible with a suitable ADB USB driver, but this procedure was verified on macOS;
  • adb from Android SDK Platform Tools;
  • a working USB data cable;
  • USB debugging enabled and the computer's RSA key accepted on the tablet.

You do not need the Android NDK, Java, Python, fastboot, an unlocked bootloader, a custom recovery, a rooting APK, or network access. The exploit and payload are statically linked.

To rebuild from source

Download Tool