Skip to content
Exploit for Use After Free in Linux Linux_Kernel

Exploit for Use After Free in Linux Linux_Kernel

Sploitus • September 30, 2026

| Fingerprint | `samsung/pa3qksx/pa3q:17/CP2A.260605.016/S938NKSUCDZIF_OKRCDZIF:user/release-keys` |

| Kernel | `6.6.127-android15-8-p33f4ffe-abogkiS938NKSUCDZIF-4k` |

| KernelSU flavour | ReSukiSU `v4.2.0-rc3`, KMI `android15-6.6` |

The support feed contains one entry, `pa3q-S938NKSUCDZIF-rsksu420`. Do not use its

offsets, exploit, or KernelSU pair on another model or firmware. The app selects by

model and kernel version; check the full firmware fingerprint above before running it.

- The device-specific CVE-2026-43499 app payload in

- The paired ReSukiSU daemon and module in `kernelsu/`.

- The target profile and P0 fingerprint under

- One schema-v3 support-feed entry in `support/targets-v3.json`.

This ReSukiSU pair is device-specific. It has not yet been validated on a handset;

the existing KernelSU- test result does not establish that ReSukiSU loads on this

device. Check the Actions build and verify ReSukiSU on the phone before treating this

In Root My Galaxy, open **Payload sources** and add:

HaSiyo/Root-My-Galaxy-Payloads-S938NKSUCDZIF-ReSukiSU

Choose the `SM-S938N` / `6.6.127` ReSukiSU profile only when the full build

fingerprint above matches your phone. A verified run loads ReSukiSU for the current

boot; rebooting clears the live kernel state.

Build the exploit payload with Android NDK r28c:

`build/pa3q-S938NKSUCDZIF/cve-2026-43499-app.so`. The **Exploit** Actions workflow

compiles the target from this repository's support feed. The **ReSukiSU** workflow

builds the paired module and daemon for the exact kernel release above and ReSukiSU

- The target-specific exploit passed its existing GitHub Actions build. The ReSukiSU

pair still requires a successful Actions build and handset validation.

- Firmware identity and kernel release were checked against the supplied device

- A handset run confirmed the separate KernelSU- flavour on this firmware. That

See the [ReSukiSU Samsung port notes](docs/RESUKISU-4.2.0-RC3-PORT.md) for the

kernel compatibility patch and its current validation status, and

[PORTING.md](docs/PORTING.md) for the general porting method.

Use only on a device you own or are explicitly authorized to test. This is a

firmware-specific research payload, not a general Samsung root package.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (2)