Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ghostlock-k419-adapter — GhostLock (CVE-2026-43499) adapter for 4.19.152-perf+ Android kernel | Kitploit
Tools/GitHubGitHub/xiaobailovesstirring/ghostlock-k419-adapter
Android SecurityPrivilege EscalationExploit FrameworksExploitationPost-ExploitationPenetration TestingMobile SecurityPayload DevelopmentBinary Exploitation

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubxiaobailovesstirring/ghostlock-k419-adapter

ghostlock-k419-adapter

GhostLock (CVE-2026-43499) adapter for 4.19.152-perf+ Android kernel

View Repository
53711 month agoNot yet reviewed

GhostLock — OnePlus Locked Bootloader Jailbreak

Kernel exploit for OnePlus/OPPO/realme devices with locked bootloader. Achieves root + KernelSU installation without unlocking bootloader or modifying boot image. Runtime auto-detection of kernel version with multi-device offset table.

GhostLock running on OnePlus Ace 6T with KernelSU (LKM, Jailbreak mode)

Vulnerability

CVE-2026-43499 — Futex PI (Priority Inheritance) Use-After-Free

Affects Linux kernel 2.6.39 ~ 7.1. Fixed in mainline 7.1 (commit 3bfdc63936dd). Android GKI 6.12.x remains vulnerable.

The pselect6 syscall copies fd_set data onto the kernel stack. When combined with the futex PI waiter mechanism, a freed stack frame can be reclaimed as an rt_mutex_waiter structure. The rb-tree rebalance during PI chain walk then writes controlled values to arbitrary kernel addresses.

Supported Devices

Verified

DeviceSoCKernelStatus
OnePlus Ace 6T (PLR110)SM88456.12.38-...-ab14275539Working
OnePlus Ace 6T (PLR110)SM88456.12.38-...-ab14552068Working
OnePlus 15 (CPH2749)SM88506.12.23-...-ab14541642Working
Xiaomi 17 (pudding)SM88506.12.23-...-abogki463945075Working
Xiaomi 17 (pudding)SM88506.12.69-...-abogki514973465Working (August 2026 update)
OnePlus 13 (IN2060)SM87506.6.89-...-abogki446052083Working (PSELECT_SHIFT=-2)
OPPO Pad 4 ProSM87506.6.89-...-ab14358676Working (PSELECT_SHIFT=-2)

Offsets Extracted (pending device test)

DeviceSoCKernelNotes
OnePlus 15T (PLZ110)SM88456.12.38-...-ab14552068Same kernel as Ace 6T. QEMU verified SP diff=-64.

Not Feasible (stack layout incompatible)

The pselect stack overlay only works when the freed rt_mutex_waiter lands within the user-controllable region of the stack_fds buffer. Where the waiter lands is determined by the compiler output (PGO + LTO), not the kernel version. See Stack Layout for details.

DeviceSoCKernelReason
OPPO Find X9 UltraSM87506.12.58-android16-6PGO eliminates do_futex frame → SP diff=+32, waiter word=14. No safe shift exists.
OPPO Find X7—6.1.1576.1 GKI: waiter at word 13 (all 6.1 OPLUS/GKI devices)
realme RMX5070SM66506.1.1416.1 GKI: waiter at word 13
realme RMX3852SM86356.1.141Same 6.1 branch as RMX5070
OnePlus 13R / Ace 5SM86506.1.xSame 6.1 branch
OnePlus 12SM86506.1.1416.1 GKI: do_futex PGO inlined, waiter word=13/19
OPPO Pad 5 (OPD2502)MT68786.1.134Same 6.1 branch
OPPO PKW110—5.15.180do_futex frame 0x140 (4.5x normal) → waiter word=-29, unreachable
Motorola Edge 60 FusionMT68786.1.1456.1 GKI: waiter at word 13 (non-OPLUS, same result)
iQOO Z9 5G—5.15.178do_futex frame too large, waiter unreachable. Not an OPLUS device (vivo).

Exploit Flow

Two root paths, selected automatically based on device capabilities:

Path A: UMH Root (preferred, C ashmem devices)

Requires off_ashmem_misc_fops != 0 (C ashmem with static miscdevice in BSS).

PI write (mode=4)  →  redirect miscdevice fops to fake fops (via W0 pi_tree)
                      configfs r/w established
                   →  pipe physrw (1-byte precise kernel r/w)
                   →  SELinux enforcing = 0 (single byte, no policycap corruption)
                   →  UMH: inject work_struct into system_unbound_wq
                      kernel executes /data/local/tmp/a/e --umh as UID 0
                   →  root script → ksud late-load → KSU installed

Advantages over Path B:

  • 1-byte SELinux write — does not corrupt selinux_state.policycap (fixes network issues on OnePlus 13)
  • No perf_event_open — works under seccomp restrictions
  • No credential patching — avoids modifying live task_struct

Currently available on: OnePlus 13 (kernel 6.6, C ashmem). Not available on Rust ashmem devices (6.12 GKI) — the miscdevice is heap-allocated, address not predictable at compile time.

Path B: Direct PI Write (fallback, all devices)

Used when UMH offsets or C ashmem misc_fops are not available.

Write 1 (mode=1)  →  SELinux enforcing = 0
                      (low byte of kernel ptr = 0x00, 8-byte write)

Write 2 (mode=2)  →  task->cred = init_cred
                      (uid=0, all capabilities)

Root shell         →  ksud late-load (KernelSU LKM)
                   →  su -c load_policy (fix SELinux policycap)
                   →  dynamic manager registration

Bootstrap Mode (phone standalone)

App (seccomp)  →  Write 1 (no perf needed)
               →  mini-adb connect TCP (port from /data/local/tmp/a/adb_port, default 5555)
               →  adb shell: full exploit (perf works, no seccomp)
               →  root → KSU → network fix

Auto-Boot (via ReSukiSU integration)

BOOT_COMPLETED → BootCompletedReceiver
  ├─ su available → skip (soft reboot / already rooted)
  └─ no root → GhostlockService → setsid exploit --bootstrap

Stack Layout Feasibility

With NFDS=320, the kernel's core_sys_select allocates a 256-byte stack_fds buffer:

stack_fds:  0    5    10   14 | 15   20   25   29
            ├─in─┤─out─┤─ex──┤ ├res_in┤res_out┤res_ex┤
            ◄── USER CONTROLLED ──►│◄── KERNEL ZEROED ──►

The exploit writes fake waiter fields (task, lock) into the fd_set input bitmaps. For this to work, the waiter's task and lock fields must fall in the controllable zone (words 0-14).

Ace 6T ✅ (waiter at word 2):
  ░░████████████████░░│░░░░░░░░░░░░░░░░░░
    ▲waiter      t  l │
    task/lock controllable

RMX5070 ❌ (waiter at word 13):
  ░░░░░░░░░░░░░████│██████████████░░░░░░
                 ▲  │    t     l
               waiter  task/lock ZEROED

Feasibility rule: waiter word + 11 (lock offset in rt_waiter_node) must be ≤ 14. Maximum feasible waiter word is 3.

The waiter position is determined by the compiler's stack frame layout (PGO + LTO + BOLT optimization profiles), which varies per SoC branch. Same kernel version can have different layouts on different SoCs.

kernel_phys_load

All kernel writes go through the image's linear-map alias:

data_addr(x) = PAGE_OFFSET + (kernel_phys_load - PHYS_OFFSET) + (x - KIMAGE_TEXT_BASE)

The bootloader picks kernel_phys_load, so it varies per SoC and is not in boot.img or the DT. Per-device field in struct kernel_offsets; 0 = use the target.h default.

SoCkernel_phys_load
SM8845 (Ace 6T, 15T)0xa8000000
SM8750 (OnePlus 13, OPPO Pad 4 Pro)0xa8000000
SM8850 (OnePlus 15, Xiaomi 17)0xc7800000

A wrong value fails silently — the write still lands in mapped RAM, so there is no crash and no effect. Don't mistake it for a PSELECT_SHIFT problem. Read it on a rooted unit of the same model (Kernel code starts at _stext; _text is 0x10000 lower):

su -c 'grep -i "Kernel code" /proc/iomem'   # c7810000-... -> 0xc7800000

PSELECT_SHIFT

Different kernels place the waiter at different positions within the controllable zone. Use PSELECT_SHIFT to adjust:

# Default (Ace 6T + OnePlus 15, 6.12): shift=0
/data/local/tmp/a/e

# OnePlus 13 (6.6): shift=-2
PSELECT_SHIFT=-2 /data/local/tmp/a/e

# Override kernel_phys_load for new SoCs (when /proc/iomem is not accessible):
KPHYS=0xc7800000 /data/local/tmp/a/e
Download Tool