Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
Log in
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
asus-i005-cve-2026-43499 — CVE-2026-43499 (GhostLock) adaptation for ASUS ROG Phone 5S — UAF trigger + pselect stack reclaim, KASLR leak blocked | Kitploit
उपकरण/GitHubGitHub/huaguiqi/asus-i005-cve-2026-43499
Android SecurityPrivilege EscalationMemory ForensicsVulnerability AnalysisExploitationReverse EngineeringMobile SecurityPapers & ResearchPayload Development

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
Binary Exploitation
GitHubhuaguiqi/asus-i005-cve-2026-43499

asus-i005-cve-2026-43499

CVE-2026-43499 (GhostLock) adaptation for ASUS ROG Phone 5S — UAF trigger + pselect stack reclaim, KASLR leak blocked

रिपॉजिटरी देखें
12719 दिन पहलेअभी तक समीक्षित नहीं
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

asus-i005-cve-2026-43499

Adaptation research of CVE-2026-43499 (GhostLock) on ASUS ROG Phone 5S (ASUS_I005).

Conclusion: Vulnerability triggering and stack reclamation fully verified; the privilege escalation chain was not completed due to insufficient stack overwrite depth.

Specifically:

  • Stages 0~1.6 all verified successfully (trigger, stack reclamation, stack address leak)
  • The write primitive in Stage 2 needs to overwrite waiter+0x28..0x40 (pi_tree_entry.rb_left and lock)
  • pselect nfds=320 only overwrites up to waiter+0x27
  • No stack reclamation carrier with deeper overwrite was found (40+ candidate syscalls exhausted)
  • All KASLR leak sources on i005 are also blocked

See docs/05-limitations.md for detailed analysis.

TL;DR

StageContentStatus
0UAF trigger (3 threads + CMP_REQUEUE_PI)✅
1pselect timeout=0 stack reclamation (shift=10)✅
1.6W kernel stack SP leak (perf PERF_SAMPLE_REGS_INTR)✅
2Arbitrary address write (requires KASLR slide)❌
—KASLR leak (all 8 sources failed)❌

Target Device

ItemValue
DeviceASUS ROG Phone 5S (ASUS_I005)
SoCSnapdragon 888 (SM8350)
Android13
Kernel5.4.210-qgki-perf-gc89cd02a7dfe arm64
SELinuxEnforcing (u:r🐚s0)
CapEff0

Vulnerability Overview

CVE-2026-43499 (GhostLock) is a stack UAF in the Linux kernel rtmutex subsystem. remove_waiter() uses current instead of waiter->task in the proxy lock rollback path, causing a dangling pointer to remain in task_struct->pi_blocked_on.

Key Results

1. pselect timeout=0 stack reclamation (original)

  • pselect timeout>0 → do_select → schedule → dangling pi_blocked_on is traversed → deadlock
  • When timeout=0, end_time=NULL, do_select returns immediately, but _copy_from_user still executes
  • nfds=320 → single copy of 40 bytes → core_sys_select uses stack_fds on the stack
  • The ex fd_set start happens to align with the waiter start → PSELECT_WAITER_WORD_SHIFT = 10

2. W kernel stack address leak

  • perf_event_open(pid=W_tid) + PERF_SAMPLE_REGS_INTR(SP)
  • Filter IRQ stacks → 41 genuine W stack samples all identical
  • 16KB alignment → sp_top → fake_waiter = sp_top - 0x1b0

3. Blocking surface — i005 hardening configuration resists all KASLR leaks

See docs/05-limitations.md:

  • kptr_restrict=2
  • perf hardware records EL0→EL1 vector entry PC on arm64 (overflow delayed)
  • perf_event_open(system-wide/kworker) EACCES
  • bpf() EACCES
  • /proc/{kallsyms,timer_list,self/stack} EACCES
  • /sys/module/*/sections EACCES

Directory Structure

  • docs/ Analysis documents and timeline
    • 06-research-snapshot.md Complete research snapshot
    • 07-iteration-log.md Failed version records
    • disasm/ Key disassembly fragments
    • recon/ Reconnaissance output
  • include/ Symbol table + struct offsets
  • src/ PoC source (see src/README.md)
  • scripts/ Analysis scripts
  • logs/ Run logs (not committed to git)

Reproduction

# 1. Extract symbols and offsets (requires vmlinux compiled from ASUS official kernel source)
./scripts/extract_symbols.sh
./scripts/gen_symbols_h.sh
./scripts/extract_offsets.sh

# 2. Compile Stage 0
aarch64-linux-gnu-gcc -static -O2 -pthread \
  -o ~/tmp/work/bin/poc_stage0_trigger src/poc_stage0_trigger.c

# 3. Run on device (requires adb shell to the target device)
adb shell /data/local/tmp/poc_stage0_trigger
Toolchain: aarch64-linux-gnu-gcc -static -O2 -pthread

References

· gitchw/ghostlock-cve-2026-43499        Huawei Watch 4 Pro, 5.4.210 (ARM32)
· ccp-p/ghostlock-cve-2026-43499-4.19-k40  Redmi K40, 4.19.157 (aarch64)
· JoinChang/ghostlock-oneplus              OnePlus multiple devices, stack layout feasibility
· knowlily/cve-2026-43499-honor            Honor failure analysis

Disclaimer

For security research only. Do not use on unauthorized devices.
टूल डाउनलोड करें