Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
cve-2026-43499-firetv-sheldonp-writeup — Security research write-up on exploiting CVE-2026-43499 on the Amazon Fire TV Stick 3rd Gen (sheldonp), from temporary root to bootloader unlock. | Kitploit
도구/GitHubGitHub/accessmodifier364/cve-2026-43499-firetv-sheldonp-writeup
Android SecurityEmbedded Systems SecurityPrivilege EscalationVulnerability AnalysisExploitationReverse EngineeringMobile SecurityHardware & IoT Security

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Papers & Research
Learning & Education
GitHubaccessmodifier364/cve-2026-43499-firetv-sheldonp-writeup

cve-2026-43499-firetv-sheldonp-writeup

Security research write-up on exploiting CVE-2026-43499 on the Amazon Fire TV Stick 3rd Gen (sheldonp), from temporary root to bootloader unlock.

저장소 보기
16818일 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-43499 on Amazon Fire TV Stick 3rd Gen (sheldonp)

Chaining a Linux kernel privilege escalation into a preloader downgrade and bootloader unlock.

License: MIT

Overview

This repository documents my authorized reproduction of the CVE-2026-43499 exploitation chain on an Amazon Fire TV Stick 3rd Gen (sheldonp). The chain used temporary kernel root to run a controlled preloader downgrade, then used the existing Kamakiri BootROM workflow to reach unlocked fastboot and complete the bootloader unlock.

This is a reproduction and device-specific case study. I did not discover CVE-2026-43499, create the original IonStack/GhostLock exploit, or develop Kamakiri. The upstream researchers and developers are credited below.

[!IMPORTANT] This write-up is a technical record, not a universal rooting guide. Build compatibility matters, temporary root is not persistent root, and mistakes involving Preloader, LK, TEE, or dm-verity-protected partitions can permanently brick the device.

Reproduction record

The end-to-end chain was completed on September 12, 2026. This repository records the tested device and software versions, the exact archives used, their SHA-256 hashes, and original evidence captured during the process.

Scope

FieldReproduction target
DeviceAmazon Fire TV Stick 3rd Gen
ModelAFTSSS
Codenamesheldonp
Operating systemFire OS 7.7.1.6 / build PS7716.5666N
Incremental0036005356164
Android baseAndroid 9
Kernel4.4.162+
Host used for BootROM stageUbuntu 26.04.1 LTS, booted as a live USB session
Android platform tools37.0.1
Temporary-root implementationR0rt1z2/GhostLock 1.1.0, 4.4 branch
BootROM implementationkamakiri-sheldon-1.0
ResultTemporary root, preloader downgrade, unlocked bootloader, TWRP, and preserved Fire OS

Out of scope: vulnerability discovery, a new exploit implementation, remote exploitation, persistent root, or support for devices other than the tested sheldonp unit. No custom ROM was installed during this reproduction.

Reproduction archives

The following are the exact ZIP archives used during this reproduction. The archives are not redistributed in this repository; their SHA-256 hashes are recorded so independently obtained copies can be compared with the files used in this case study.

ArchiveSourceVersionSHA-256
ghostlock-sheldon-v1.1.0.zipTemporary-root and downgrade guide on XDAGhostLock 1.1.08D541F7DF58487AF6D6D45D778482D3455A71F62E32651751CFE0B2DDFC6554F
kamakiri-sheldon-1.0.zipBootloader-unlock guide on XDAKamakiri Sheldon 1.01B07161D9F894935E5918A9B8F9A230F67B9487E9863C242E758338E8C6C5784

These hashes identify the copies used in this case study; readers should still compare their downloads against the original upstream sources and review the applicable third-party licenses.

Technical background

CVE-2026-43499, also known as GhostLock, is a use-after-free in the Linux kernel's priority-inheritance futex/rtmutex path. During proxy-lock rollback, remove_waiter() operated on current instead of the task stored in waiter->task. As a result, the actual waiter could return to userspace with pi_blocked_on still referencing an rt_mutex_waiter in a released kernel stack frame.

The original IonStack research turns that dangling stack reference into a local privilege-escalation primitive. R0rt1z2 adapted the technique to the Fire TV Stick 3rd Gen and Fire TV Stick Lite (sheldonp/sheldon) running Fire OS 7 on a 4.4 kernel.

The key distinction in this case study is that CVE-2026-43499 does not unlock the bootloader directly. It provides temporary kernel-level access. That short-lived access makes it possible to perform the controlled preloader downgrade required before the older Kamakiri BootROM chain can run.

Exploit chain

flowchart LR
    A[Fire OS 7 on sheldonp] --> B[CVE-2026-43499 / GhostLock]
    B --> C[Temporary root shell]
    C --> D[Controlled preloader downgrade]
    D --> E[Expected non-booting transition state]
    E --> F[Kamakiri BootROM stage]
    F --> G[Unlocked fastboot]
    G --> H[Bootloader unlocked]

The chain crosses two separate security boundaries:

  1. Kernel boundary: an unprivileged local process gains a temporary root context through GhostLock.
  2. Boot-chain boundary: temporary root prepares the device for a known BootROM-based unlock path by restoring a compatible preloader.

Methodology

1. Establish the baseline

Before changing the device, I identified the hardware codename and recorded the Fire OS, build, bootloader, and kernel versions over ADB.

adb devices -l
adb shell getprop ro.product.device
adb shell getprop ro.product.model
adb shell getprop ro.build.version.release
adb shell getprop ro.build.version.incremental
adb shell getprop ro.build.fingerprint
adb shell getprop ro.bootloader
adb shell uname -a
adb shell id

The resulting baseline was sheldonp / AFTSSS, Fire OS PS7716.5666N, incremental 0036005356164, Android 9, and kernel 4.4.162+. The serial number is deliberately omitted.

ADB shell baseline showing the unprivileged shell context

2. Obtain temporary root with GhostLock

I connected the Fire TV over USB with ADB debugging enabled and used GhostLock 1.1.0, the sheldon/sheldonp package published with the R0rt1z2 XDA guide. The device-specific launcher reboots the Fire TV to start from a fresh state, deploys the exploit, and retries when necessary.

Successful exploitation creates a temporary root environment. I verified the security context from an ADB shell rather than treating script completion alone as proof:

adb shell
su
id

The root context is ephemeral and is lost on reboot. That behavior is important: this stage is an enabling primitive for the downgrade, not the final persistence mechanism or the bootloader unlock itself.

The successful run showed uid=0, changed SELinux to permissive for the temporary environment, mounted the temporary su, and disabled the Fire OS OTA packages handled by the tool.

GhostLock root shell showing uid 0 and OTA package changes

The full GhostLock exploit trace is retained as supporting evidence.

3. Downgrade the preloader

With temporary root available, I used the package's dedicated downgrade workflow instead of manually writing firmware partitions. This restored a preloader compatible with the existing Kamakiri path.

After the downgrade, the Fire TV intentionally stopped booting into Fire OS. In this specific workflow, that non-booting state is the expected handoff between the live-kernel stage and the USB BootROM stage. It must not be confused with proof that an arbitrary failed flash is recoverable.

도구 다운로드