DF-0472 / leak_sample.txt
DF-0472 leaked-kernel-heap sample (rule cmd region, 1020 bytes, cmd_len=255 bug)
Captured on the UNPATCHED #0 module. The first 8 bytes are our MARKER cmd;
bytes [8..1019] are LEAKED kernel heap (krealloc tail + neighbour slab over-read).
Content varies run-to-run (genuine heap residue), kernel pointers are stable in form.
--- run 1 (this verification) ---
MARKER (cmd[0..7]): de 01 be ad ef 01 03 02
Leaked tail (cmd[0x3c0..0x3ff]), the over-read boundary:
03c0: 00 2f 72 6f 6f 74 2f 2e 73 73 68 2f 61 75 74 68 "/root/.ssh/auth"
03d0: 6f 72 69 7a 65 64 2f 72 6f 6f 74 00 00 00 00 00 "orized/root"
03e0: 00 00 00 00 00 00 00 00 00 00 00 00 60 5a 11 81
03f0: ff ff ff ff 20 5a 11 81 ff ff ff ff
=> kernel pointers: 0xffffffffff81115a60 / 0xffffffff81115a20 (little-endian
uint64: 60 5a 11 81 ff ff ff ff == 0xffffffff81115a60)
=> ASCII path "/root/.ssh/authorized/root" (namecache / vnode-path buffer)
LEAK SUMMARY: 42 / 1012 bytes non-zero in leaked region
first non-zero leaked byte at cmd[961], last at cmd[1019]
--- runs 2 & 3 ---
Same mechanism; rule list grows (ADD accumulates), GET returns 2168 / 3228 bytes.
Each garbage rule's cmd region still carries kernel heap residue in its tail.