Feed/CVE-2026-43499
CVE-2026-43499HIGHCVSS 7.8

CVE-2026-43499

Published May 21, 2026·Updated Aug 22, 2026

NVD Description

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]

Public Exploits & PoCs100 found

PoC: ghostlock-app

GhostLock One-Tap Execution App (CVE-2026-43499)

508

PoC: IonStack-S22U

CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)

37

[POC] CVE-2026-43499 — CVE-2026-43499-popsicle

CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k

21

[POC] CVE-2026-43499 — CVE-2026-43499-Neo11Plus

the CVE-2026-43499 by iqooneo11

18

PoC: ghostlock-s26

GhostLock (CVE-2026-43499) for the Galaxy S26

7

PoC: pixel-ksu-root

adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.

5

[POC] CVE-2026-43499 — GhostLock-Galaxy

Root your Galaxy using CVE-2026-43499

4

PoC: iQOO-Z9_5G-vivo-T3_5G-Root-GhostLock

An iQOO Z9 5G and vivo T3 5G jailbreak/root CVE-2026-43499 Android application and payloads. Both devices use the MediaTek Dimensity 7200 (MT6886) platform. Kernel version 5.15.178.

4

PoC: Root-My-Galaxy

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

4

[POC] CVE-2026-43499 — Mi8E5-Unlocker-by-CVE-2026-43499

基于 CVE-2026-43499 的 8E5 机型自动化解锁辅助工具,仅限授权安全研究与自有设备使用。

3

[POC] CVE-2026-43499 — tcp-zerocopy-sm

ghostlock + tcp-zerocopy hybrid CVE-2026-43499 port

2

[POC] CVE-2026-43499 — root-my-s9280

Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))

2

[POC] CVE-2026-43499 — ghostlock-oneplus

GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader

2

[POC] GHSA-8qqm-fp2q-v734 — CVE-2026-43499-S25U

Galaxy S25 Ultra SM-S938N S938NKSUACZF1 port of CVE-2026-43499

2

[POC] CVE-2026-43499 — GhostLock-5.10

Kernel root exploit (CVE-2026-43499) for some 5.X devices (mostly Amazon)

1

[POC] CVE-2026-43499 — ghostlock-cve-2026-43499-4.19-k40

CVE-2026-43499 (GhostLock) rtmutex remove_waiter() UAF local-root PoC adapted for Qualcomm Android 4.19 kernels (Redmi K40 / Snapdragon 870 class), LD_PRELOAD based

1

PoC: cve-2026-43499-honor

CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.

1

PoC: KSuRoot

KSuRoot 2.2.0 — One-click KernelSU rooting based on CVE-2026-43499. Synced from Root-My-Galaxy v0.2.6 with custom payload (.so) import. Mod by hmascs

1

PoC: iqoo-temp-root

vivo/iQOO 临时 root 工具箱 (免解锁临时root, CVE-2026-43499) - 源码与脚本

1

PoC: ghostlock-apk

独立 APK:CVE-2026-43499 GhostLock 提权 + Shizuku shell 身份执行

1

PoC: ghostlock-honor-aak-probe

该仓库已经确认此漏洞利用不可能实现、已判死刑,永久性停止更新。基于 CVE-2026-43499 (rtmutex remove_waiter UAF) 的 GhostLock exploit 半成品工程,KASLR 绕过 / 提权 / su 植入等环节均无法稳定利用,本项目永久终止。

1

PoC: ghostlock-honor-aak

GhostLock (CVE-2026-43499) exploit adapted for Honor AAK-AN00 (MagicOS 10, kernel 6.6.89-android15)

1

PoC: HORiZonstack

CVE-2026-43499 for the Meta Quest

1

PoC: CVE-2026-43499

CVE-2026-43499: Linux kernel futex PI use-after-free research package

1

PoC: GhostLock-for-OnePlus15T

(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.

1

PoC: GhostLock-for-OnePlus

(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加设备。

1

PoC: oppo-A5-PRO-5G-CVE-2026-43499

本次个人漏洞研究进展成果

1

PoC: SpringPeace

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

1

PoC: oppo-ghostlock

OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation

1

PoC: rmg-s9180-fzg1

Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM

PoC: ghostlock-infinix-hot70

Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.

PoC: vivo-root-build

vivo/iQOO 提权 so 编译(CVE-2026-43499)

PoC: RootMyVivo

One-click root for vivo/iQOO devices on locked bootloader | CVE-2026-43499 + KernelSU

PoC: ghostlock-k419-adapter

GhostLock (CVE-2026-43499) adapter for 4.19.152-perf+ Android kernel

PoC: CVE-2026-43499-NAM-AL00

Security research: CVE-2026-43499 GhostLock on Huawei Nova 9 NAM-AL00 (SM7325, HMOS 4.2, kernel 5.4.86-qgki)

PoC: CyberMeowfiaNS

The next stage of CyberMeowfil (CVE-2026-43499 and 43074),Possibly biased toward vivo devices?

PoC: GhostLock-H80GT

Honor 80 GT (MagicOS 8.0.0.128, kernel 5.10.168) privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loading

PoC: GhostLock_MT6983V_5.10

High-risk vulnerability CVE-2026-43499, implementation on the 5.10 kernel and MediaTek MT6983V

PoC: s26-m1q-ghostlock-selinux

GhostLock CVE-2026-43499 research for Galaxy S26 (SM-S942U1/m1q): SELinux Permissive achieved, KASLR + tracefs port, uid=0 boundary documented

PoC: ghostlock-custom

GhostLock (CVE-2026-43499) adaptation for non-Android Linux 6.x ARM64

PoC: CVE-2026-43499_HW-CLT-AL01

尝试移植CVE-2026-43499提权漏洞到HW P20Pro上

PoC: ghostlock-cve-2026-43499

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

PoC: ghostlock-a17

CVE-2026-43499 port for Samsung Galaxy A17

PoC: IonStack-S22-cve-2026-43499

Full root in kernel domain with selinux permissive

PoC: CVE-2026-43499-ZFOLD4

CVE-2026-43499 research port for Galaxy Z Fold4 SM-F936W F936WVLU1AVGA (in progress)

PoC: cve-2026-43499-m3q-azf1

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved here.

PoC: GhostLock

CVE-2026-43499 futex PI stack UAF ???????? - Android GKI 6.1~6.12 ??????? pselect() + futex PI ????????????,??? root ??? SELinux??? OPPO Find X8?OnePlus ??????

PoC: F9360-CVE43499

SM-F9360 (Galaxy Z Fold4, q4q) locked-bootloader KernelSU root — CVE-2026-43499 temp root → LD_PRELOAD DEFEX bypass → no-LTO clang-12 kernelsu.ko. Device-verified 2026-08-12.

PoC: GhostLock-OPPO-PCKM00

CVE-2026-43499 GhostLock futex UAF LPE PoC for OPPO PCKM00 (SM6150) / Linux 4.14.180

PoC: ghostlock-skeleton-v2

CVE-2026-43499 GhostLock APK 骨架 — 从零开始,仅空项目编译验证

PoC: ghostlock-skeleton

CVE-2026-43499 GhostLock APK 骨架 — 仅验证空项目能编译通过

PoC: ghostlock-x200-root

GhostLock-X200 v1.0 - temporary root toolchain for vivo X200 (PD2415 / b57 kernel) based on CVE-2026-43499. For authorized security research only.

PoC: GhostLock-GOT-W29

CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29

PoC: Root-My-Galaxy-tests

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499 (Note: Fork)

PoC: Root-My-Galaxy

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

PoC: ghostlock-sm-a155f

GhostLock (CVE-2026-43499) kernel exploit for samsung devices with locked bootloader

PoC: CVE-2026-43499_x86_Exploit

CVE-2026-43499 x86 Exploit

PoC: ghostlock-myron-tw

GhostLock (CVE-2026-43499) kernel exploit port for REDMI K90 Pro Max Taiwan firmware (myron, WPMTWXM) — offsets, build guide, prebuilt binary

PoC: Root-My-Pixel

Jailbreak supported Google Pixel phones with CVE-2026-43499

PoC: CVE-2026-43499-S26

Root prototype for Galaxy S26

PoC: CVE-2026-43499-A36

Standalone CVE-2026-43499 port for Galaxy A36 5G SM-A366W A366WVLS3AYG1 with KernelSU late-load

PoC: cve-2026-43499

PD2229B的43499(ghostlock)可行性研究

PoC: ghostlock-aresin

GhostLock (CVE-2026-43499) exploit for POCO F3 GT (aresin) — MediaTek Dimensity 1200, Linux 4.14.186 ARM64 kernel privilege escalation via futex PI chain manipulation

PoC: ghostlock-emerald

GhostLock (CVE-2026-43499) kernel exploit for Poco M6 Pro (emerald) with locked bootloader

PoC: mt6985-CVE-2026-43499

CVE-2026-43499 exploit adapter for MT6985 MediaTek Dimensity 9300 (vivo PD2241)

PoC: Root-My-Device

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

PoC: CVE-2026-43499-root-KernelSU

基于内核漏洞的本地提权适配,集成嵌入式 KernelSU 。编译生成`preload.so`;触发成功后会以 `late-load` 模式(越狱模式)启动 KernelSU。支持(xbl_config.img / vendor_boot.img) + boot.img 生成target.h Local privilege escalation adaptation based on a kernel vulnerability, integrating embedded KernelSU. Compiles and generates `preload.so`; , KernelSU will be started in `late-load` mode

PoC: CVE-2026-43499-S24U

CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (in progress)

PoC: UnPlus

CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)

PoC: cve-2026-43499-CyberMeowfia

最原始的

PoC: rmx3888-cve-2026-43499-config

CVE-2026-43499 exploit configuration for realme RMX3888 (Android 16) - 20 verified kernel offsets

PoC: CVE-2026-43499-PoC-Scanner

CVE-2026-43499 PoC Scanner

PoC: Ace3-GhostLock-Preload

OnePlus Ace 3 preload.so for CVE-2026-43499 (GhostLock)

PoC: CVE-2026-43499-Redmi-Turbo5

Use CVE-2026-43499 on Redmi Turbo 5 to escalate privilege

PoC: CVE-2026-43499

CVE-2026-43499

PoC: CVE-2026-43499-cloudflare-gate

CVE-2026-43499-cloudflare-gate签名授权计算

PoC: CVE-2026-43499-For-Xiaomi-17T-chagall

CVE-2026-43499 reproduce in Xiaomi 17T. (kernelsu incomplete)

PoC: CVE-2026-43499

CVE-2026-43499

PoC: smt878u-ionstack-poc

CVE-2026-43499 (IonStack/GhostLock) pure-C re-root POC for Samsung SM-T878U / gts7l (T878USQS8DXE1)

PoC: ghostlock-selinux-disabler

Use CVE-2026-43499 to disable SELinux on Android

PoC: vivo-x-fold6-ghostlock

vivo X Fold6 (V2545A) GhostLock CVE-2026-43499 临时root/永久解锁研究

PoC: CyberMeowfia-ace3

CVE-2026-43499 exploit with OnePlus Ace3 support

PoC: CVE-2026-43499-jinghu

CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)

PoC: CVE-2026-43499-jinghu

CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)

PoC: CyberMeowfia-ace3

CVE-2026-43499 exploit with OnePlus Ace3 support

PoC: ghostlock-rothko

CVE-2026-43499 GhostLock exploit for Redmi K70 Ultra (rothko) - data-only physmap overwrite

PoC: CVE-2026-43499-popsicle

CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k

PoC: auto_extract_offsets

CvE-2026-43499偏移量计算

PoC: CVE-2026-43499

A modified method to root Android device with locked bootloader via new exploit. (Only for Samsung now or smthing like that devices cuz i ported it to N970U1), Fork of https://github.com/localhosts-A/CyberMeowfia

PoC: duchamp-root

Xiaomi K70e (duchamp) one-click root via CVE-2026-43499 (IonStack) + KernelSU integration

PoC: Logitech-G-Cloud-GhostLock-CVE-2026-43499

罗技云掌机 · GhostLock CVE-2026-43499 root 尝试

PoC: CVE-2026-43499-Poc-Analysis

Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.

PoC: CVE-2026-43499-Poc-Analysis

Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.

PoC: SpringPeace

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

PoC: Android-CVE-2026-43499

Android version CVE-2026-43499 tester

PoC: oppo-pgem10-ghostlock

OPPO Find X6 Pro GhostLock (CVE-2026-43499) exploit adaptation

PoC: Mi8E5-Unlocker-by-CVE-2026-43499

Multi OS Support: Version for MacOS/Linux and Windows, Fully translated to English

PoC: openvz-cve-patch-2026

GhostLock - CVE-2026-43499 backport patch for openVZ 7

PoC: ghostlock

Tracking GhostLock (CVE-2026-43499), the rtmutex/futex stack use-after-free

PoC: CVE-2026-43499

CVE-2026-43499

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free