Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
ghost-hoock — GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge. | Kitploit
Outils/GitHubGitHub/genksome/ghost-hoock
Android SecurityPrivilege EscalationMemory ForensicsVulnerability AnalysisExploitationMobile SecurityPapers & ResearchPayload DevelopmentBinary Exploitation
GitHubgenksome/ghost-hoock

ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

451il y a 20 joursPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Voir le dépôt
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

ghost-hoock

A minimal fork of GhostLock that keeps only one primitive: turning off SELinux via CVE-2026-43499 (futex PI UAF).

ghost-hoock running on Samsung A17

kernel device cve license platform


Table of contents

  • What is this
  • How it works
  • What was kept from the original
  • What was removed
  • Building
  • Running
  • Requirements
  • Limitations and risks
  • Project layout
  • License
  • Credits
  • Links

What is this

ghost-hoock is a stripped-down fork of the GhostLock exploit by Mobile Hacking Lab, reduced to a single primitive:

One constrained write via futex PI UAF -> selinux_enforcing = 0.

No root, no cred overwrite, no rwforge channel, no UMH, no configfs. Just the minimum needed to flip SELinux into permissive mode on the vulnerable kernel.

Example output on a Samsung Galaxy A17 (SM-A175F, BZA5):


[] kernel: 6.12.23-android16-5-abA175FXXS5BZD2-4k
[+] offsets matched: 6.12.23-android16-5-abA175FXXS5BZD2-4k
[] init_cred image=ffffffc082512b08 alias=ffffff8002512b08
[+] startup context pid=10331 uid=2000 euid=2000 gid=2000 egid=2000 attr=u:r:shell:s0 enforce=1
[+] startup limits pid=10331 NoNewPrivs=0 Seccomp=0 Seccomp_filters=0
[+] build config pid=10331 label=ghost-hoock
[] p0 kernel_phys_load=0000000040000000 delta=0000000000000000 core=0
[] target selinux_enforcing=ffffff800277e560
[] W1 attempt 1/20
[] === W1: SELinux === target=0xffffff800277e560 mode=1
[] prepare_kernel_page ok attempt=1
[] pselect route setup simple=0 shift=0 page=ffffff806c4f0000 fake_lock=ffffff806c4f0000 ...
[] pselect returned ret=6 errno=0 calls=1 success=1 delay=0
[] pselect route done calls=1 success=1 step=0 errno=0
[+] SELinux DISABLED (attempt 1)

Then:

$ getenforce
Permissive

getenforce returns Permissive


How it works

The exploit targets CVE-2026-43499 — a use-after-free in the Linux kernel's futex PI (Priority Inheritance) rt_mutex chain. The chain in ghost-hoock is four steps:

1. KernelSnitch mm_struct leak

Timing side-channel against the kernel's futex hash table. We hammer FUTEX_WAKE_PRIVATE on a set of user-space futexes, measure rdtsc deltas, and correlate hash-bucket collisions. This recovers the address of our own mm_struct — the base of the spray page we later need.

This is the KernelSnitch technique, taken verbatim from the original exploit.

2. Heap spray

We allocate a large order-3 slab page, then lay it out with the fake-object layout used by the PI route:

OffsetObjectPurpose
0x0E80fake_lockFake rt_mutex
0x0F80fake_fopsFake file_operations table
0x1180fake_w0Fake rt_mutex_waiter used as target tree
0x1240fake_rightFake rb-tree right node — this is where the write value comes from
0x1260fake_leftFake rb-tree left node
0x1280fake_taskFake task_struct

The whole page is sent through an AF_UNIX socket as SKB_SEND_SIZE = 2 * ORDER3_SIZE of sendmsg, so the skb data lands on our leaked page. Then we free it in a controlled order so that our page ends up on a per-cpu partial slab we can reclaim.

3. PI route

Three threads:

  • waiter — enters FUTEX_WAIT_REQUEUE_PI on f_wait, targeting f_pi_target.
  • owner — holds FUTEX_LOCK_PI on f_pi_target and then on f_pi_chain.
  • consumer — spins calling sched_setattr(tid, SCHED_BATCH, nice=19) on the waiter's TID, which triggers rt_mutex_setprio() and forces the kernel to walk the fake PI tree.

A fourth call from the main thread — FUTEX_CMP_REQUEUE_PI(1, f_pi_target) — kicks off the requeue. Inside the kernel, rb_erase() runs against our fake tree.

4. pselect constrained write

pselect() / select() copies the user's fd_set into kernel stack and later walks it. We arrange the fd_set bitmaps so that the words the kernel treats as rb-tree pointers land on fake_right and its parent — and the resulting rb_set_parent(child, parent) becomes:


*(uint64_t *)target = value | color

For mode = 1 (Write 1), target = selinux_enforcing and value = base + 0x100, which encodes as byte0 = 0, byte1 = 1. The kernel writes 0 to selinux_enforcing[0] — SELinux is now permissive.

ret = 6 (instead of the default 9) confirms the write landed: the consumer hit the target during select(), waking it early.


What was kept from the original

This is a fork of mobilehackinglab/ghostlock-a17 (MIT). The following is taken 1:1 from the upstream exploit:

ComponentFileNotes
KernelSnitchsrc/kernelsnitch/*mm_struct leak via futex hash timing
Heap spraysrc/spray.cfake-object layout, prepare_skb_payload, prepare_kernel_page
PI route + pselectsrc/route.cprepare_pselect_fdsets, do_pselect_fake_lock_route, consumer_thread, waiter_thread, owner_thread
BZA5 offsetsinclude/offsets_bza5.hSymbol table extracted from 6.12.23-android16-5-abA175FXXS5BZD2-4k
BZA5 target headerinclude/target.hAddress layout, payload offsets (W1-subset only)
Runtime struct offsetsinclude/runtime_struct_offsets.h_RSO() macros for task_struct fields

Auxiliary code (pr_* macros, SYSCHK, pin_to_core, set_limit, set_unbuffer) is also kept as-is from the original.


What was removed

The original GhostLock achieves full root on the A17: it installs a rwforge physical R/W channel, patches cred / real_cred, runs a UMH helper with init creds, captures logs, and more. In ghost-hoock, everything past the first constrained write is gone.

Removed fileWhy it existed in the original
rwforge_a17.cMarching-forger physical R/W channel via pipe_buffers
pipe_physrw.c, pipe_reclaim.cPipe-buffer reclaim -> arbitrary kernel read/write
root.ccred / real_cred overwrite, su install, SELinux SID patching
umh_root.c, wq_umh_root() (in main.c)Running an init-creds helper from a forged kernel workqueue item
slide.cKASLR leak via boot_id oracle — not needed on BZA5, KASLR is off
miniadb.cBootstrap via ADB TCP
try_cfi_stage() (in fops.c)CFI-friendly configfs stage used to bootstrap the root path
run_rwforge(), run_bootid_oracle(), rwforge_root_and_capture()The whole root pipeline
install_embedded_su(), install_embedded_wallpaper()Root-install helpers
Write 2 (cred), patch_cred_*, patch_task_seccompPost-W1 credential takeover
Télécharger l’outil