DragonFlyBSD Kernel Audit
DF-0739 / leak_sample.txt
← back to finding ↓ download raw
=== DF-0739 pointer-leak sample (baseline, 128B request, unpatched #0) ===
12 candidate 0xffff... kernel pointers disclosed in over-read region:
  0000: 00 00 00 00 00 00 00 00 00 00 00 00 80 26 0a 4f 
  0010: 00 f8 ff ff 30 09 60 82 ff ff ff ff 00 00 00 00 
  0020: 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 
  0030: 00 00 00 00 20 21 0a 4f 00 f8 ff ff 20 0b 60 82 
  0040: ff ff ff ff 00 00 00 00 00 00 00 00 02 00 00 00 
  0050: 00 00 00 00 01 00 00 00 1c 00 00 00 2f 75 73 72 
  0060: 2f 6c 69 62 65 78 65 63 2f 67 65 74 74 79 00 50 
  0070: 63 00 74 74 79 76 33 00 00 00 00 00 
non-zero bytes in over-read region: 59 / 124
candidate 64-bit kernel pointers (0xffff...): 8

=== earlier string-leak sample (3 runs @ 128B) — adjacent slab objects ===
=== DF-0739 baseline leak sample (3 runs @ 128B) ===

--- RUN 1 ---
ctx->sets (first 4 bytes, the only legitimate field):
  0000: 00 00 00 00 
Over-read past ctx->sets: 124 bytes (heap residue):
  0000: 00 00 00 00 01 00 00 00 1c 00 00 00 2f 75 73 72 
  0010: 2f 6c 69 62 65 78 65 63 2f 67 65 74 74 79 00 50 
  0020: 63 00 74 74 79 76 35 00 00 00 00 00 00 00 00 00 
  0030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0070: 00 00 00 00 00 00 00 00 00 00 00 00 
non-zero bytes in over-read region: 27 / 124
candidate 64-bit kernel pointers (0xffff...): 0

--- RUN 2 ---
ctx->sets (first 4 bytes, the only legitimate field):
  0000: 00 00 00 00 
Over-read past ctx->sets: 124 bytes (heap residue):
  0000: 00 00 00 00 01 00 00 00 1c 00 00 00 2f 75 73 72 
  0010: 2f 6c 69 62 65 78 65 63 2f 67 65 74 74 79 00 50 
  0020: 63 00 74 74 79 76 35 00 00 00 00 00 00 00 00 00 
  0030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0070: 00 00 00 00 00 00 00 00 00 00 00 00 
non-zero bytes in over-read region: 27 / 124
candidate 64-bit kernel pointers (0xffff...): 0

--- RUN 3 ---
ctx->sets (first 4 bytes, the only legitimate field):
  0000: 00 00 00 00 
Over-read past ctx->sets: 124 bytes (heap residue):
  0000: 00 00 00 00 01 00 00 00 1c 00 00 00 2f 75 73 72 
  0010: 2f 6c 69 62 65 78 65 63 2f 67 65 74 74 79 00 50 
  0020: 63 00 74 74 79 76 35 00 00 00 00 00 00 00 00 00 
  0030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 
  0070: 00 00 00 00 00 00 00 00 00 00 00 00 
non-zero bytes in over-read region: 27 / 124
candidate 64-bit kernel pointers (0xffff...): 0

=== large read @ 1024B (tail) ===
getsockopt returned 1024 bytes (requested 1028 payload after 4-byte x_header)
ctx->sets (first 4 bytes, the only legitimate field):
  0000: 00 00 00 00 
Over-read past ctx->sets: 1020 bytes (heap residue):
  0000: 00 00 00 00 01 00 00 00 1c 00 00 00 2f 75 73 72 
  0010: 2f 6c 69 62 65 78 65 63 2f 67 65 74 74 79 00 50 
  0020: 63 00 74 74 79 76 35 00 00 00 00 00 00 00 00 00 
  0030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00