Skip to content
Exploit for Use After Free in Linux Linux_Kernel

Exploit for Use After Free in Linux Linux_Kernel

Sploitus • September 30, 2026

| Fingerprint | `samsung/pa3qksx/pa3q:17/CP2A.260605.016/S938NKSUCDZIF_OKRCDZIF:user/release-keys` |

| Kernel | `6.6.127-android15-8-p33f4ffe-abogkiS938NKSUCDZIF-4k` |

| KernelSU flavour | Official KernelSU `v3.3.0`, KMI `android15-6.6` |

The support feed contains one entry, `pa3q-S938NKSUCDZIF-ksu330`. Do not use its

offsets, exploit, or KernelSU pair on another model or firmware. The app selects by

model and kernel version; check the full firmware fingerprint above before running it.

- The device-specific CVE-2026-43499 app payload in

- The paired official KernelSU daemon and Samsung-patched module in `kernelsu/`.

- The target profile and P0 fingerprint under

- One schema-v3 support-feed entry in `support/targets-v3.json`.

The exploit payload and official KernelSU `v3.3.0` pair passed GitHub Actions

build and feed-publication checks. The module is built with the Samsung KDP/RKP/Defex

patch in `kernelsu/patches/KernelSU-v3.3.0-samsung-kdp-rkp-defex.patch`. The

KernelSU Manager and on-device KernelSU connection have not yet been validated for

this separate flavour; a KernelSU- handset result does not establish that.

In Root My Galaxy, open **Payload sources** and add:

For compatibility with app builds that only accept the built-in artifact URL prefixes, this

repository's feed uses the upstream catalog URL as a path alias. When this repository is selected,

the app pins each artifact path to this source's own commit before downloading it; the upstream

repository is not used as the artifact host.

Choose the `SM-S938N` / `6.6.127` official KernelSU profile only when the full build

fingerprint above matches your phone. KernelSU is loaded for the current boot;

Build the exploit payload with Android NDK r28c:

`build/pa3q-S938NKSUCDZIF/cve-2026-43499-app.so`. The **Exploit** Actions workflow

compiles the target from this repository's support feed. The **KernelSU** workflow

builds the Samsung-patched official KernelSU module and paired daemon for the exact

kernel release above and version `v3.3.0`.

- The target-specific exploit and official KernelSU `v3.3.0` pair passed GitHub Actions builds.

- The publish workflow verified the module version, exact kernel release, daemon pairing,

and artifact digests before updating the support feed.

- Firmware identity and kernel release were checked against the supplied device

- Full handset validation of this official KernelSU flavour is still pending.

See the [device port report](docs/ports/pa3q-S938NKSUCDZIF/port-report.md) for the

audit and remaining runtime checks, and [PORTING.md](docs/PORTING.md) for the

Use only on a device you own or are explicitly authorized to test. This is a

firmware-specific research payload, not a general Samsung root package.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (2)

Tools (1)