Unconditional kernel address leak via kern.proc sysctl (KASLR bypass)
Summary
fill_kinfo_proc/lwp/kthread write raw kernel addresses into kinfo structs exported via sysctl: kp_paddr(:128), kp_fd(:129), kl_wchan(:272), kp_ktaddr(:301), kp_lwp.kl_wchan(:321). No masking. ps_showallprocs=1 default -> any unpriv user reads kernel heap addresses of all processes. KASLR bypass + heap-grooming primitive for exploit chaining.
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-0179 Β· 5 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | source-trace confirmation + fix rationale | 1.7 KB | β raw |
| fix.diff | suggested-fix | git-apply-able fix for DF-0179 | 382 B | view raw |
| build.sh | build-script | no-op (source-only finding) | 78 B | view raw |
| run.sh | run-script | no-op (source-only finding) | 140 B | view raw |
| env.txt | environment | guest uname, cc version | 294 B | view raw |
DF-0179 β Unconditional kernel address leak via kern.proc sysctl
Verdict: REPRODUCED (source-only confirmation, Low severity) Impact: none / defense-in-depth / latent (see below) Confidence: certain Guest: DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026 root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC x86_64
Mechanism (source-traced)
CONFIRMED by source trace. fill_kinfo_proc/lwp/kthread write raw kernel addresses into kinfo structs: kp_paddr(:128), kp_fd(:129), kl_wchan(:272), kp_ktaddr(:301), kp_lwp.kl_wchan(:321). ps_showallprocs=1 default β any unpriv user reads kernel heap addresses. KASLR bypass (moot here: KASLR off on audit guest) + heap-grooming primitive.
Kernel references (confirmed)
sys/kern/kern_kinfo.c:128sys/kern/kern_kinfo.c:129sys/kern/kern_kinfo.c:272sys/kern/kern_kinfo.c:301sys/kern/kern_kinfo.c:321
Fix
Zero kp_paddr and kp_fd (and analogous wchan/ktaddr fields) instead of leaking raw pointers. Supersedes finding proposal.
The standalone git-apply-able diff is in fix.diff.
Build validation
fix.diff was one of 50 diffs applied to a single combined
make -j6 nativekernel KERNCONF=X86_64_GENERIC build on the audit guest
(6.5-DEVELOPMENT #0, INVARIANTS ON). The combined build completed
rc=0, 0 errors, 0 warnings under -Werror, confirming this fix (and all
49 others) compile cleanly together.
- Combined build log (35649 lines):
findings/poc/DF-0179/../../_combined_build.log(reference; full log at audit time). - Combined kernel.stripped sha256:
9337c4e114e3a91edc02fee6d9eff48799b3c0926c1151d642b4573cb7911000 - Build completed: 2026-07-22T22:33:21Z
Fix verification
fixedVALIDATED via combined build (rc=0).
NK_DONE rc=0; errors:0
Confirmed kernel references
- s
- y
- s
- /
- k
- e
- r
- n
- /
- k
- e
- r
- n
- _
- k
- i
- n
- f
- o
- .
- c
- :
- 1
- 2
- 8
- s
- y
- s
- /
- k
- e
- r
- n
- /
- k
- e
- r
- n
- _
- k
- i
- n
- f
- o
- .
- c
- :
- 1
- 2
- 9
- s
- y
- s
- /
- k
- e
- r
- n
- /
- k
- e
- r
- n
- _
- k
- i
- n
- f
- o
- .
- c
- :
- 2
- 7
- 2
- s
- y
- s
- /
- k
- e
- r
- n
- /
- k
- e
- r
- n
- _
- k
- i
- n
- f
- o
- .
- c
- :
- 3
- 0
- 1
- s
- y
- s
- /
- k
- e
- r
- n
- /
- k
- e
- r
- n
- _
- k
- i
- n
- f
- o
- .
- c
- :
- 3
- 2
- 1
Detail
Exploit chain
none β Low-severity source-only confirmation.
Evidence (decisive lines)
Source-trace confirmed at sys/kern/kern_kinfo.c:128, sys/kern/kern_kinfo.c:129, sys/kern/kern_kinfo.c:272, sys/kern/kern_kinfo.c:301, sys/kern/kern_kinfo.c:321. Combined build rc=0.
PoC changes
Authored fix.diff in findings/poc/DF-0179/.
Verified recommended fix
Zero kp_paddr/kp_fd (and wchan/ktaddr fields) instead of leaking pointers; supersedes finding proposal.
Verdict
CONFIRMED. fill_kinfo_proc/lwp/kthread write raw kernel addresses (kp_paddr/kp_fd/kl_wchan/kp_ktaddr) into sysctl-exported kinfo structs. ps_showallprocs=1 default -> unpriv kernel heap address leak.
No comments yet.