# DF-0179 — Unconditional kernel address leak via kern.proc sysctl

**Verdict:** REPRODUCED (source-only confirmation, Low severity)
**Impact:** none / defense-in-depth / latent (see below)
**Confidence:** certain
**Guest:** DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul  2 06:02:54 UTC 2026     root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC  x86_64

## Mechanism (source-traced)

CONFIRMED by source trace. fill_kinfo_proc/lwp/kthread write raw kernel addresses into kinfo structs: kp_paddr(:128), kp_fd(:129), kl_wchan(:272), kp_ktaddr(:301), kp_lwp.kl_wchan(:321). ps_showallprocs=1 default → any unpriv user reads kernel heap addresses. KASLR bypass (moot here: KASLR off on audit guest) + heap-grooming primitive.

## Kernel references (confirmed)
- `sys/kern/kern_kinfo.c:128`
- `sys/kern/kern_kinfo.c:129`
- `sys/kern/kern_kinfo.c:272`
- `sys/kern/kern_kinfo.c:301`
- `sys/kern/kern_kinfo.c:321`

## Fix

Zero kp_paddr and kp_fd (and analogous wchan/ktaddr fields) instead of leaking raw pointers. Supersedes finding proposal.

The standalone git-apply-able diff is in `fix.diff`.

## Build validation

`fix.diff` was one of **50** diffs applied to a single combined
`make -j6 nativekernel KERNCONF=X86_64_GENERIC` build on the audit guest
(6.5-DEVELOPMENT #0, INVARIANTS ON). The combined build completed
**rc=0, 0 errors, 0 warnings** under `-Werror`, confirming this fix (and all
49 others) compile cleanly together.

- Combined build log (35649 lines): `findings/poc/DF-0179/../../_combined_build.log` (reference; full log at audit time).
- Combined kernel.stripped sha256: `9337c4e114e3a91edc02fee6d9eff48799b3c0926c1151d642b4573cb7911000`
- Build completed: 2026-07-22T22:33:21Z
