Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
tcp-zerocopy-sm — ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel | Kitploit
उपकरण/GitHubGitHub/meowkis/tcp-zerocopy-sm
Android SecurityPrivilege EscalationExploitationMobile SecurityBinary ExploitationArchived
GitHubmeowkis/tcp-zerocopy-sm

tcp-zerocopy-sm

ghostlock + tcp-zerocopy hybrid CVE-2026-43499 adaptation for samsung kernel

रिपॉजिटरी देखें
2141 महीना पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Investigation is closed. Working fork: https://github.com/soumarcelino/Root-My-Galaxy-SM-S918B

Read this -> https://github.com/BuSung-dev/Root-My-Galaxy-Payloads/issues/160#issuecomment-5227077583

Version License License

Attempts to cause rights elevation w GhostLock via TCP Zerocopy.

Designed expecially for 5.15.* samsung kernel

[!WARNING] Do not rely on current payload tests. After reviewing the exploit code more carefully, I realized I had misidentified the CVEs associated with the TCP zerocopy path. The standalone payload tests I ran were incorrect. Isolated payload tests without the full exploit chain prove nothing. I will update this issue once the complete port is tested.

[!IMPORTANT] The only reliable way to determine if this vector still works on the SM-S918B is to port the full Pixel 9 exploit (including the GhostLock dangling waiter setup, CFI stage, and configfs R/W primitives) and observe whether it reaches main tcp route done=1. I will continue working on this port, but there is no ETA.

🚧 Work in progress (v0.1):
Investigating the flow to build porting strategy .

Project

CyberMeowfia/exploit/src/ is reference only! Samsung device config was added for testing here and doesn't mean anything. The actual port will be in src/

Current target

PropertyValue
DeviceSamsung Galaxy S23 Ultra, dm3q / SM-S918B
BuildS918BXXSAFZF5
Android version16
Kernel5.15.189-android13-8-33413713-abS918BXXSAFZF5
Fingerprintsamsung/dm3qxxx/dm3q:16/BP4A.251205.006/S918BXXSAFZF5:user/release-keys
ArchitectureARM64
Kernel text base0xffffffc008000000
Physical base0x80000000
Physical kernel load address0x80080000

Test payloads are stored in payloads/. The active constants are stored in target.h.

You can verify if your S23 family phone is vulnerable by compiling and running test_tcp_zc.c

Compiling

export NDK=~/Android/Sdk/ndk/android-ndk-r29 #path_to_ndk

$NDK/toolchains/llvm/prebuilt/linux-x86_64/bin/aarch64-linux-android29-clang -static -O2 test_tcp_zc.c -o test_tcp_z

Running the penetration test

adb push test_tcp_zc /data/local/tmp/
adb shell chmod +x /data/local/tmp/test_tcp_zc
adb shell /data/local/tmp/test_tcp_zc

What should be happened

If kernel panics then is vulnerable to this exploit!

Kimi's analyzed fops.c

Click to view
टूल डाउनलोड करें