Skip to content

默认将superkey固定为"su"导致的任意进程提权 #142

Description

@can-xin

Please check before submitting an issue | 在提交 Issue 前请检查

  • I searched the issues and didn't found anything relevant | 我已经搜索了 Issues 列表,没有发现于本问题相关内容
  • If the patch fails or the image cannot be booted after flashing the new boot.img, visit KernelPatch to clarify your doubts | 修复失败或刷入修补后镜像不能启动,请前往 KernelPatch 提问
  • I will upload the bug report file in APatch Manager > Settings > Send logs | 我会上传 Bug Report 文件从 APatch 管理器 > 设置 > 发送日志
  • I know how to reproduce the issue, which might not be specific to my device | 我知道如何重新复现这个问题

Version requirements | 版本要求

  • I'm using the latest CI version of APatch Manager | 我正在使用最新 CI 版本

Bug description | 描述 Bug

在最新的FolkPatch修补流程中,通过kptools -S su,将kpimg中的superkey 写死为公开的字符串 "su",这导致了任意用户提权,这种固定密钥的设计不应出现

Reproduce method | 复现方法

调用supercall的任意功能,superkey传"su"即可复现

Expected behavior | 预期行为

Actual behavior | 实际行为

Screenshots | 截图

Image

Logs | 日志

No response

Device name | 设备名称

moto g54

OS version | 系统版本

android 15

APatch version | FolkPatch 版本

4.3

Kernel version | 内核版本

5.10

KernelPatch version | KernelPatch 版本

0.31.1

Other information | 其他信息

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions