Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
tcp-zerocopy-sm — ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel | Kitploit
Outils/GitHubGitHub/meowkis/tcp-zerocopy-sm
Android SecurityPrivilege EscalationExploitationMobile SecurityBinary ExploitationArchived
GitHubmeowkis/tcp-zerocopy-sm

tcp-zerocopy-sm

ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel

Voir le dépôt
215il y a 1 moisPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

Investigation is closed. Working fork: https://github.com/soumarcelino/Root-My-Galaxy-SM-S918B

Read this -> https://github.com/BuSung-dev/Root-My-Galaxy-Payloads/issues/160#issuecomment-5227077583

Version License License

Attempts to cause rights elevation w GhostLock via TCP Zerocopy.

Designed expecially for 5.15.* samsung kernel

[!WARNING] Do not rely on current payload tests. After reviewing the exploit code more carefully, I realized I had misidentified the CVEs associated with the TCP zerocopy path. The standalone payload tests I ran were incorrect. Isolated payload tests without the full exploit chain prove nothing. I will update this issue once the complete port is tested.

[!IMPORTANT] The only reliable way to determine if this vector still works on the SM-S918B is to port the full Pixel 9 exploit (including the GhostLock dangling waiter setup, CFI stage, and configfs R/W primitives) and observe whether it reaches main tcp route done=1. I will continue working on this port, but there is no ETA.

🚧 Work in progress (v0.1):
Investigating the flow to build porting strategy .

Project

CyberMeowfia/exploit/src/ is reference only! Samsung device config was added for testing here and doesn't mean anything. The actual port will be in src/

Current target

PropertyValue
DeviceSamsung Galaxy S23 Ultra, dm3q / SM-S918B
BuildS918BXXSAFZF5
Android version16
Kernel5.15.189-android13-8-33413713-abS918BXXSAFZF5
Fingerprintsamsung/dm3qxxx/dm3q:16/BP4A.251205.006/S918BXXSAFZF5:user/release-keys
ArchitectureARM64
Kernel text base0xffffffc008000000
Physical base0x80000000
Physical kernel load address0x80080000

Test payloads are stored in payloads/. The active constants are stored in target.h.

You can verify if your S23 family phone is vulnerable by compiling and running test_tcp_zc.c

Compiling

export NDK=~/Android/Sdk/ndk/android-ndk-r29 #path_to_ndk

$NDK/toolchains/llvm/prebuilt/linux-x86_64/bin/aarch64-linux-android29-clang -static -O2 test_tcp_zc.c -o test_tcp_z

Running the penetration test

adb push test_tcp_zc /data/local/tmp/
adb shell chmod +x /data/local/tmp/test_tcp_zc
adb shell /data/local/tmp/test_tcp_zc

What should be happened

If kernel panics then is vulnerable to this exploit!

Kimi's analyzed fops.c

Click to view
Télécharger l’outil