Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
asus-i005-cve-2026-43499 — CVE-2026-43499 (GhostLock) adaptation for ASUS ROG Phone 5S — UAF trigger + pselect stack reclaim, KASLR leak blocked | Kitploit
도구/GitHubGitHub/huaguiqi/asus-i005-cve-2026-43499
Android SecurityPrivilege EscalationMemory ForensicsVulnerability AnalysisExploitationReverse EngineeringMobile SecurityPapers & ResearchPayload Development

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Binary Exploitation
GitHubhuaguiqi/asus-i005-cve-2026-43499

asus-i005-cve-2026-43499

CVE-2026-43499 (GhostLock) adaptation for ASUS ROG Phone 5S — UAF trigger + pselect stack reclaim, KASLR leak blocked

저장소 보기
12719일 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

asus-i005-cve-2026-43499

Adaptation research of CVE-2026-43499 (GhostLock) on ASUS ROG Phone 5S (ASUS_I005).

Conclusion: Vulnerability triggering and stack reclamation fully verified; the privilege escalation chain was not completed due to insufficient stack overwrite depth.

Specifically:

  • Stages 0~1.6 all verified successfully (trigger, stack reclamation, stack address leak)
  • The write primitive in Stage 2 needs to overwrite waiter+0x28..0x40 (pi_tree_entry.rb_left and lock)
  • pselect nfds=320 only overwrites up to waiter+0x27
  • No stack reclamation carrier with deeper overwrite was found (40+ candidate syscalls exhausted)
  • All KASLR leak sources on i005 are also blocked

See docs/05-limitations.md for detailed analysis.

TL;DR

StageContentStatus
0UAF trigger (3 threads + CMP_REQUEUE_PI)✅
1pselect timeout=0 stack reclamation (shift=10)✅
1.6W kernel stack SP leak (perf PERF_SAMPLE_REGS_INTR)✅
2Arbitrary address write (requires KASLR slide)❌
—KASLR leak (all 8 sources failed)❌

Target Device

ItemValue
DeviceASUS ROG Phone 5S (ASUS_I005)
SoCSnapdragon 888 (SM8350)
Android13
Kernel5.4.210-qgki-perf-gc89cd02a7dfe arm64
SELinuxEnforcing (u:r🐚s0)
CapEff0

Vulnerability Overview

CVE-2026-43499 (GhostLock) is a stack UAF in the Linux kernel rtmutex subsystem. remove_waiter() uses current instead of waiter->task in the proxy lock rollback path, causing a dangling pointer to remain in task_struct->pi_blocked_on.

Key Results

1. pselect timeout=0 stack reclamation (original)

  • pselect timeout>0 → do_select → schedule → dangling pi_blocked_on is traversed → deadlock
  • When timeout=0, end_time=NULL, do_select returns immediately, but _copy_from_user still executes
  • nfds=320 → single copy of 40 bytes → core_sys_select uses stack_fds on the stack
  • The ex fd_set start happens to align with the waiter start → PSELECT_WAITER_WORD_SHIFT = 10

2. W kernel stack address leak

  • perf_event_open(pid=W_tid) + PERF_SAMPLE_REGS_INTR(SP)
  • Filter IRQ stacks → 41 genuine W stack samples all identical
  • 16KB alignment → sp_top → fake_waiter = sp_top - 0x1b0

3. Blocking surface — i005 hardening configuration resists all KASLR leaks

See docs/05-limitations.md:

  • kptr_restrict=2
  • perf hardware records EL0→EL1 vector entry PC on arm64 (overflow delayed)
  • perf_event_open(system-wide/kworker) EACCES
  • bpf() EACCES
  • /proc/{kallsyms,timer_list,self/stack} EACCES
  • /sys/module/*/sections EACCES

Directory Structure

  • docs/ Analysis documents and timeline
    • 06-research-snapshot.md Complete research snapshot
    • 07-iteration-log.md Failed version records
    • disasm/ Key disassembly fragments
    • recon/ Reconnaissance output
  • include/ Symbol table + struct offsets
  • src/ PoC source (see src/README.md)
  • scripts/ Analysis scripts
  • logs/ Run logs (not committed to git)

Reproduction

# 1. Extract symbols and offsets (requires vmlinux compiled from ASUS official kernel source)
./scripts/extract_symbols.sh
./scripts/gen_symbols_h.sh
./scripts/extract_offsets.sh

# 2. Compile Stage 0
aarch64-linux-gnu-gcc -static -O2 -pthread \
  -o ~/tmp/work/bin/poc_stage0_trigger src/poc_stage0_trigger.c

# 3. Run on device (requires adb shell to the target device)
adb shell /data/local/tmp/poc_stage0_trigger
Toolchain: aarch64-linux-gnu-gcc -static -O2 -pthread

References

· gitchw/ghostlock-cve-2026-43499        Huawei Watch 4 Pro, 5.4.210 (ARM32)
· ccp-p/ghostlock-cve-2026-43499-4.19-k40  Redmi K40, 4.19.157 (aarch64)
· JoinChang/ghostlock-oneplus              OnePlus multiple devices, stack layout feasibility
· knowlily/cve-2026-43499-honor            Honor failure analysis

Disclaimer

For security research only. Do not use on unauthorized devices.
도구 다운로드