
ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel
Read this -> https://github.com/BuSung-dev/Root-My-Galaxy-Payloads/issues/160#issuecomment-5227077583
[!WARNING] Do not rely on current payload tests. After reviewing the exploit code more carefully, I realized I had misidentified the CVEs associated with the TCP zerocopy path. The standalone payload tests I ran were incorrect. Isolated payload tests without the full exploit chain prove nothing. I will update this issue once the complete port is tested.
[!IMPORTANT] The only reliable way to determine if this vector still works on the SM-S918B is to port the full Pixel 9 exploit (including the GhostLock dangling waiter setup, CFI stage, and configfs R/W primitives) and observe whether it reaches main tcp route done=1. I will continue working on this port, but there is no ETA.
🚧 Work in progress (
v0.1):
Investigating the flow to build porting strategy .
CyberMeowfia/exploit/src/ is reference only! Samsung device config was added for testing here and doesn't mean anything. The actual port will be in src/
| Property | Value |
|---|---|
| Device | Samsung Galaxy S23 Ultra, dm3q / SM-S918B |
| Build | S918BXXSAFZF5 |
| Android version | 16 |
| Kernel | 5.15.189-android13-8-33413713-abS918BXXSAFZF5 |
| Fingerprint | samsung/dm3qxxx/dm3q:16/BP4A.251205.006/S918BXXSAFZF5:user/release-keys |
| Architecture | ARM64 |
| Kernel text base | 0xffffffc008000000 |
| Physical base | 0x80000000 |
| Physical kernel load address | 0x80080000 |
Test payloads are stored in payloads/.
The active constants are stored in target.h.
You can verify if your S23 family phone is vulnerable by compiling and running test_tcp_zc.c
Compiling
export NDK=~/Android/Sdk/ndk/android-ndk-r29 #path_to_ndk
$NDK/toolchains/llvm/prebuilt/linux-x86_64/bin/aarch64-linux-android29-clang -static -O2 test_tcp_zc.c -o test_tcp_z
Running the penetration test
adb push test_tcp_zc /data/local/tmp/
adb shell chmod +x /data/local/tmp/test_tcp_zc
adb shell /data/local/tmp/test_tcp_zc
What should be happened
If kernel panics then is vulnerable to this exploit!