KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

Published 26 Aug 2026Updated 26 Aug 2026177 sources
CVSS 7.8 HIGH✓ VERIFIED REFERENCE

What happened

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
CVE-Intel · BuSung-dev/Root-My-GalaxyKSU installer for supported Samsung Galaxy firmware with CVE-2026-43499ExploitKotlinHIGHAwaiting Analysis★ 925⑂ 185EPSS 0.77%CVE data: CNACode indexedUpdated 26 Aug 2026BuSung-dev2026-07-17VerifiedCVE-Intel · rsyzee/ghostlock-infinix-hot70Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.PoCHIGHAwaiting Analysis★ 0⑂ 0EPSS 0.77%CVE data: CNAUpdated 26 Aug 2026rsyzee2026-08-26CandidateCVE-Intel · JoinChang/ghostlock-oneplusGhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloaderExploitCHIGHAwaiting Analysis★ 284⑂ 60EPSS 0.77%CVE data: CNACode indexedUpdated 26 Aug 2026Tags: android, coloros, ghostlock, kernelsu, oneplus, rootJoinChang2026-07-12CandidateCVE-Intel · alex193a/Root-My-PixelJailbreak supported Google Pixel phones with CVE-2026-43499ExploitKotlinHIGHAwaiting Analysis★ 217⑂ 44EPSS 0.77%CVE data: CNACode indexedUpdated 26 Aug 2026Tags: cve, exploit, google, jailbreak, pixel, rootalex193a2026-08-02CandidateCVE-Intel · yakidango-official/GhostLock-H80GTHonor 80 GT privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loadingLPECHIGHAwaiting Analysis★ 3⑂ 3EPSS 0.77%CVE data: CNACode indexedUpdated 26 Aug 2026yakidango-official2026-08-23CandidateCVE-Intel · Linuxoid-cn/CVE-2026-43499-Poc-AnalysisVulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.PoCCHIGHAwaiting Analysis★ 77⑂ 24EPSS 0.77%CVE data: CNACode indexedUpdated 26 Aug 2026Linuxoid-cn2026-07-14CandidateCVE-Intel · CakesTwix/Android-CVE-2026-43499Android version CVE-2026-43499 testerExploitKotlinHIGHAwaiting Analysis★ 59⑂ 8EPSS 0.77%CVE data: CNACode indexedUpdated 26 Aug 2026CakesTwix2026-07-13CandidateCVE-Intel · JingMatrix/pixel-ksu-rootadb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.ExploitCHIGHAwaiting Analysis★ 8⑂ 2EPSS 0.77%CVE data: CNACode indexedUpdated 26 Aug 2026JingMatrix2026-08-25CandidateNanoTurtle1145/root-my-s24Using CVE-2026-43499 to root your Galaxy S24 Series(SM-S92X0 ,(China / Hong Kong SAR / Taiwan))★ 36NanoTurtle11452026-08-16CandidateYuKongA/ghostlock-appGhostLock One-Tap Execution App (CVE-2026-43499)★ 728YuKongA2026-07-29Candidatesarabpal-dev/IonStack-S22UCVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)★ 65sarabpal-dev2026-08-08VerifiedCxyofficial/K50G-POCOF4GT-CVE-2026-43499-PoC★ 0Cxyofficial2026-09-01Verifiedlkeld/CVE-2026-43499-poc★ 2lkeld2026-09-01Verifiedankitrawatgit/iQOO-Z9_5G-vivo-T3_5G-Root-GhostLockAn iQOO Z9 5G and vivo T3 5G jailbreak/root CVE-2026-43499 Android application and payloads. Both devices use the MediaTek Dimensity 7200 (MT6886) platform. Kernel version 5.15.178.★ 8ankitrawatgit2026-08-22Candidatezzzxxxxxxxxxx/GhostLock-GOT-W29CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29★ 4zzzxxxxxxxxxx2026-08-10Candidate