Skip to content

默认将superkey固定为"su"导致的任意进程提权 #142

@can-xin

Description

@can-xin

Please check before submitting an issue | 在提交 Issue 前请检查

  • I searched the issues and didn't found anything relevant | 我已经搜索了 Issues 列表,没有发现于本问题相关内容
  • If the patch fails or the image cannot be booted after flashing the new boot.img, visit KernelPatch to clarify your doubts | 修复失败或刷入修补后镜像不能启动,请前往 KernelPatch 提问
  • I will upload the bug report file in APatch Manager > Settings > Send logs | 我会上传 Bug Report 文件从 APatch 管理器 > 设置 > 发送日志
  • I know how to reproduce the issue, which might not be specific to my device | 我知道如何重新复现这个问题

Version requirements | 版本要求

  • I'm using the latest CI version of APatch Manager | 我正在使用最新 CI 版本

Bug description | 描述 Bug

在最新的FolkPatch修补流程中,通过kptools -S su,将kpimg中的superkey 写死为公开的字符串 "su",这导致了任意用户提权,这种固定密钥的设计不应出现

Reproduce method | 复现方法

调用supercall的任意功能,superkey传"su"即可复现

Expected behavior | 预期行为

Actual behavior | 实际行为

Screenshots | 截图

Image

Logs | 日志

No response

Device name | 设备名称

moto g54

OS version | 系统版本

android 15

APatch version | FolkPatch 版本

4.3

Kernel version | 内核版本

5.10

KernelPatch version | KernelPatch 版本

0.31.1

Other information | 其他信息

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions