Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
lenovo_y700_tb320fc_on_CVE-2025-21479 — In-memory kernel privilege escalation for Lenovo Legion Y700 2023 (TB320FC) exploiting CVE-2025-21479, a Qualcomm Adreno GPU SMMU flaw, with ReSukiSU root management. | Kitploit
도구/GitHubGitHub/xjoker/lenovo_y700_tb320fc_on_cve-2025-21479
Android SecurityPrivilege EscalationPersistence MechanismsExploitationMobile App PentestingPost-ExploitationMobile SecurityPayload DevelopmentBinary Exploitation

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHubxjoker/lenovo_y700_tb320fc_on_cve-2025-21479

lenovo_y700_tb320fc_on_CVE-2025-21479

In-memory kernel privilege escalation for Lenovo Legion Y700 2023 (TB320FC) exploiting CVE-2025-21479, a Qualcomm Adreno GPU SMMU flaw, with ReSukiSU root management.

저장소 보기
3719일 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

TB320FC Kernel Root — CVE-2025-21479

English | 简体中文

In-memory kernel privilege escalation for the Lenovo Legion Y700 2023 (TB320FC), exploiting CVE-2025-21479 (Qualcomm Adreno GPU SMMU vulnerability), with full root management provided by ReSukiSU.

No bootloader unlock. No flashing. No PC required for activation.

⚠️ For authorized security research on devices you own. See Disclaimer.


Target Device

All offsets and behavior in this project are tuned for the following device. Do not expect it to work on other models/ROMs without retuning (see exploit/device_info.txt).

ModelLenovo Legion Y700 2023 (TB320FC) / TB320FC_PRC
SoCQualcomm SM8475 (Snapdragon 8+ Gen 1, Adreno 730)
SystemZUXOS 1.1.350 / Android 15 (SDK 35)
BuildAQ3A.240812.002 (TB320FC_CN_OPEN_USER_Q00031.0_V_ZUXOS_1.1.350_ST_250418)
Kernel5.10.209-android12-9-gef44381c3e04-ab50
Security patch2025-03-05
BootloaderLocked (this project does not unlock it)

Verified working as of 2026-09 on the above firmware.

Features

CapabilityImplementation
Privilege escalationcheese exploit: KGSL SMMU bug → GPU arbitrary physical R/W → in-memory root (uid 0 + full caps)
Root managementReSukiSU (KernelSU fork) in late-load mode loads kernelsu.ko; su served by an in-kernel hook (u:r:ksu:s0)
SELinuxRestored to Enforcing after activation (ReSukiSU policy rules stay applied)
One-tap UXRootActivator APK with embedded exploit + ksud; a single tap after boot
Auto-recovery (optional)Boot-triggered self-healing chain: adaptive load-gated trigger → cheese → root pipeline → optional hosts/Vector. Off by default (com.poc.roottool.CONFIG)
Xposed modulesSupported via NeoZygisk (ptrace zygote injection) + Vector
PersistenceNone by design (in-memory): re-activate after each reboot (~3-4 min; or enable the auto-recovery chain)

Screenshots

RootActivator (activated)ReSukiSU (working, 2 modules)
RootActivatorReSukiSU

Left: RootActivator after successful activation — SELinux Enforcing, kernelsu loaded, su available. Right: ReSukiSU manager — LKM mode working with 2 modules (NeoZygisk + Vector).

How It Works

RootActivator APK
   │
   ├─ libcheese.so ── KGSL SMMU exploit (CVE-2025-21479)
   │     1. Adreno 730 microcode access-check flaw (SDS packet mistaken for RingBuffer)
   │     2. Fake CP_SMMU_TABLE_UPDATE overwrites GPU TTBR0 → arbitrary physical R/W
   │     3. Zero selinux_state.enforcing; dump kernel from fixed PA 0xA8000000,
   │        parse kallsyms from the raw image (SM8475 has no physical KASLR)
   │     4. Patch __do_sys_capset with an escalation shellcode
   │        (prepare_kernel_cred(0) + commit_creds + clear TIF_SECCOMP);
   │        forked child calls capset() → uid 0 + full caps
   │
   └─ libksud.so (ReSukiSU) ── late-load mode
         1. kernelsu.ko loaded from ksud's embedded assets with manual relocation
            (does not rely on kernel symbol exports)
         2. install → /data/adb/ksu (ksud/busybox/bootctl)
         3. su channel online: /system/bin/su → kernel hook redirect → u:r:ksu:s0
         4. setenforce 1 — Enforcing restored, policy rules already injected by the ko

Notable engineering points

  • Qualcomm GKI trims kernel symbol exports. 77 symbols required by upstream KernelSU are missing, so a plain insmod kernelsu.ko fails. ReSukiSU's late-load resolves symbols itself and loads fine.
  • CPU affinity fix in cheese. With multiple cores, patched kernel text can be executed with stale instructions on another core (I-cache coherence), causing a panic. Pinning the process to one core makes the exploit far more reliable.
  • Load sensitivity. During the post-boot initialization storm (5-10 min) the failure rate is significantly higher. See docs/TROUBLESHOOTING.md.

Quick Start

1. Get RootActivator

Build from source (see Building) or grab the APK from the GitHub Releases page (not stored in the repo).

2. Install ReSukiSU manager

Download from ReSukiSU Releases and install the manager APK.

3. Activate

  1. After boot, wait 5-10 minutes (the tool auto-detects system load and waits if needed)
  2. Open RootActivator → tap Activate Root
  3. Wait 3-4 minutes (progress is shown in the built-in log)
  4. When done, open the ReSukiSU manager and grant root to your apps (Shizuku, terminals, ...)

4. (Optional) Xposed module support

  1. Install NeoZygisk (via ReSukiSU manager → Modules → install from storage)
  2. Install Vector (Xposed framework)
  3. After root is active, start the injector on the device (activation does not do this):
    su -c 'sh /data/adb/modules/zygisksu/post-fs-data.sh'
    
  4. Details in docs/VECTOR.md

Repository Layout — PoC + activator

The repo contains the PoC (the exploit) and its one-tap activator. The custom device layers (debloat scripts, privacy-hosts module, Xposed scope tooling, bring-up helpers) are kept out of tree in a separate private archive — they are deliberately not part of this repository. Details: docs/ARCHITECTURE.md.

├── LICENSE / CHANGELOG.md
├── README.md / README.zh-CN.md
│
├── exploit/            the PoC — root acquisition (CVE-2025-21479)
│   ├── source/         cheese.c / kallsyms_lookup.c / adrenaline.h
│   ├── device_info.txt Target device parameters (offsets, verified facts)
│   ├── build.sh        Build script (requires Android NDK)
│   └── README.md       Boundary statement, runtime chain, known failure modes
│
├── app/                RootActivator — one-tap activator (all extras OFF by default)
│   ├── src/            BootReceiver / HealGuardService / HealConfig / MainActivity (Kotlin)
│   ├── assets/         selfheal.sh / waiter.sh / xposed-up.sh
│   ├── native/         libcheese.so + libksud.so (built from exploit/; see tools/fetch_assets.py)
│   ├── AndroidManifest.xml
│   ├── debug.keystore  debug signing key used by the public APK
│   ├── build.py        Build script (kotlinc + d8 + aapt2 + apksigner)
│   └── README.md       App documentation
│
├── tools/              Build / inspection helpers
│   ├── fetch_assets.py         Host: prepare native assets (exploit + ksud)
│   ├── status_check.sh         On-device: root / module snapshot
│   └── check_mods.sh           On-device: module inspection helper
├── docs/               Documentation (English)
│   ├── ARCHITECTURE.md         Chains, engineering notes, root-cause records
│   ├── TROUBLESHOOTING.md      Failure handling, success-rate data
│   └── VECTOR.md               Xposed (NeoZygisk + LSPosed/Vector) setup
└── screenshots/        On-device PNG evidence

Building

exploit (Android NDK)

cd exploit
NDK=/path/to/android-ndk ./build.sh
# Produces ./cheese (arm64) → used as app/native/libcheese.so

RootActivator APK

도구 다운로드