KernelSU LKM vs GKI: Why LKM Is the Way Now, and How to Install It
Since v3.0, KernelSU officially supports only LKM mode. What LKM and GKI mean, how to check support and match your KMI, and how to install KernelSU with the manager.
KernelSU puts root inside the Android kernel. Since version 0.9.0 it has had two ways of doing that on GKI devices: LKM mode loads KernelSU as a module into your phone’s own kernel, and GKI mode replaces the kernel with a generic one that has KernelSU built in.
Since version 3.0, KernelSU no longer supports GKI mode officially. Its build guide says so, and the files of the current release, 3.3.0, contain LKM modules for each kernel interface but no GKI kernel images. KernelSU’s installation page still describes both modes, so keep that in mind when you read it alongside this guide.
Everything here needs an unlocked bootloader, and unlocking usually wipes the phone. Back up first.
Step 1: Is your device supported?
Install the KernelSU manager and open it:
- Not installed means your device is officially supported. Continue below.
- Unsupported means you would have to build a kernel yourself.
Step 2: Three things to understand
KMI (Kernel Module Interface). Kernels with the same KMI are compatible. The KMI is the w.x-zzz-k part of your kernel version. For example, 5.10.101-android12-9-g30979850fc20 has the KMI 5.10-android12-9. The sub-level (101) is not part of it. KernelSU’s LKM modules are built per kernel interface: the 3.3.0 release has them from android12-5.10 up to android17-6.18.
Security patch level. Newer devices may have anti-rollback protection, so an image with an older security patch level than your device’s can cause a boot loop.
Kernel version is not Android version. A phone that launched with Android 12 usually keeps its android12-5.10 kernel after updating to Android 13 or later. Always go by the kernel version, not the Android version.
LKM or GKI today
| LKM mode | GKI mode | |
|---|---|---|
| What it does | Loads KernelSU as a module into your stock kernel | Replaces your kernel with one that has KernelSU built in |
| Official support | Yes | No, since version 3.0; no kernel images are published |
| Updating KernelSU | From the manager, no manual flashing | Flash a new kernel |
| After a system update (OTA) | Install to the inactive slot from the manager | Flash again |
| Turn root off temporarily | ksud unload from a root shell, no reboot |
No |
| Works with a custom kernel | Yes, patch that kernel’s image | Replaces it |
| Samsung with Knox | Doesn’t work | Only with a kernel you build or get elsewhere |
For a phone, that leaves LKM. Even before version 3.0, the project advised phones to prefer it.
Installing in LKM mode
LKM patches the ramdisk. On devices that have an init_boot partition, which launched with Android 13 or later, the manager patches init_boot; otherwise it patches boot.
- Open the manager and tap the install icon in the top right. In version 3.3.0 the options are:
- Select a file and patch: pick your stock image. See how to extract boot.img if you don’t have it. The manager asks you to make sure it is a stock image, and since 3.3.0 you can choose Backup as stock image so it keeps the original for later restores.
- Download a file and patch: new in 3.3.0. Enter the address of a full OTA or factory image, and the manager downloads it and patches the image itself, so you don’t have to extract anything.
- Direct install (Recommended): only on a device that already has root. The manager patches and flashes in one go. This is also the normal way to update KernelSU.
- Install to inactive slot (After OTA): only with root, on devices with A/B slots, after a system update. The manager patches the other slot, then you reboot into it.
- Advanced options let you choose the partition yourself or use a local LKM file.
- Flash the patched image if you patched a file: the guide’s words are “just flash this patched file”. Flash it to the partition it came from with fastboot, the tool KernelSU’s guide uses for flashing, for example
fastboot flash init_boot <patched image>, orbootif that is what you patched. Then reboot. - Or patch on a computer:
ksud boot-patch -b <boot.img> --kmi android13-5.10patches an image on macOS, Linux or Windows. Each release includesksudbuilds for all three.
What about GKI mode?
The last releases with GKI kernel images were the 2.x series. If you have a kernel with KernelSU built in, because you built it or got it from a third party, you flash it like any custom kernel. The old warnings still apply: the kernel has to match your KMI and security patch level, and the compression format of your stock kernel (for example lz4 or gz). A mismatch can cause a boot loop.
After installing: modules
Modules that only use scripts, sepolicy or system.prop work straight away. Modules that change files in /system need a metamodule, and KernelSU’s docs point to the official meta-overlayfs. When we checked, the documentation’s download link for it didn’t work, so look for its current location on KernelSU’s GitHub. For Xposed-style modules you also need Zygisk and a framework. See how to install LSPosed.
Not sure KernelSU is right for your phone? Compare it with APatch and Magisk in KernelSU vs APatch vs Magisk.
Apps in this guide
-
KernelSU The manager app for KernelSU, a root solution built into the Android kernel. It grants root per app and manages modules.Download -
APatch The manager for APatch, which roots Android by patching the kernel image and supports both Magisk-style and kernel modules.Download -
Payload Dumper Extracts boot.img and other partition images from an OTA zip or payload.bin on the phone, with hash verification.Download
Sources
- KernelSU installation guide checked Sep 30, 2026
- KernelSU: how to build (GKI image mode dropped since v3.0) checked Sep 30, 2026
- KernelSU metamodules checked Sep 30, 2026
- KernelSU v3.3.0 release (notes and files) checked Sep 30, 2026